Reflected Cross-site scripting Vulnerability in Teamcenter
A reflected cross-site scripting vulnerability exists in the authentication redirect flow (/auth/) of Siemens Teamcenter. An unauthenticated attacker can craft a malicious URL containing injected JavaScript that executes within an authenticated user's session. Successful exploitation allows the attacker to read sensitive data or perform actions on behalf of the victim within Teamcenter, such as accessing design files, stealing intellectual property, or modifying product data. The vulnerability affects Teamcenter V2412 (before 2412.0013), V2506 (before 2506.0010), V2512 (before 2512.2607), and V2606 (before 2606.2607).
- User must be logged into Teamcenter
- User must click a malicious link provided by the attacker
- No special network access required; exploitation occurs via URL injection in the browser
Patching may require device reboot — plan for process interruption
/api/v1/advisories/f2d31a90-c4df-4de2-be2c-6b19a857909fGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.