The pentest professionals at usd HeroLab identified several vulnerabilities during a web application and fat-client penetration test. These include two cross-site scripting vulnerabilities in the Teamcenter web application, as well as hardcoded credentials in Siemens Teamcenter, which, under certain conditions, would allow unauthorized access to sensitive functions or information.
Additionally, three XML External Entity (XXE) vulnerabilities were identified during a fat-client penetration test of Schneider Electric’s EcoStruxure Building Operation. Among other things, these vulnerabilities allow attackers to read local files, access internal resources, and launch denial-of-service attacks.
The vulnerabilities were reported to the vendors as part of the Responsible Disclosure Policy. Detailed information about the advisories can be found here:
| ID | Product | Vulnerability Type |
|---|---|---|
| usd-2025-36 | Teamcenter | Use of Hard-coded Credentials (CWE-798) |
| usd-2025-37 | Teamcenter | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79) |
| usd-2025-38 | Teamcenter | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') (CWE-79) |
| usd-2025-43 | EcoStruxure Building Operation | Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') (CWE-776) |
| usd-2025-44 | EcoStruxure Building Operation | Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion') (CWE-776) |
| usd-2025-45 | EcoStruxure Building Operation | Improper Restriction of XML External Entity Reference (CWE-611) |
About usd HeroLab Security Advisories
In order to protect businesses against hackers and criminals, we must ensure that our skills and knowledge are up to date at all times. Therefore, security research is just as important to our work as is building up a security community to promote an exchange of knowledge. After all, more security can only be achieved if many people take on the task.
We analyze attack scenarios, which are changing constantly, and publish a series of Security Advisories on current vulnerabilities and security issues – always in line with our Responsible Disclosure Policy.
Always in the name of our mission: “more security.”



