Siemens IAM Client Untrusted Search Path Privilege Escalation (CVE-2025-40945)
First seen Jul 23, 2026 · Updated Jul 23, 2026 · CVSS 6.7
Multiple Siemens industrial and engineering software products bundling the IAM Client SDK are affected by an untrusted/unquoted search path vulnerability that could allow an authenticated local attacker to escalate privileges. Siemens has released patched versions for most affected products and recommends updating as soon as possible, with fixes pending for remaining products.
Technical Analysis
CVE-2025-40945 is an Untrusted Search Path vulnerability (CWE-426) in the Siemens IAM Client SDK, scoring CVSS v3.1 6.7 (AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H). A local authenticated attacker could exploit insecure DLL/executable search path resolution to plant a malicious binary that gets loaded with elevated privileges, resulting in full compromise of confidentiality, integrity, and availability on the host. The vulnerability affects a wide range of Siemens engineering, simulation, and PLM products (COMOS, Solid Edge, Teamcenter Visualization, Simcenter suite, Tecnomatix) that embed the vulnerable IAM Client component. This is a local privilege escalation vector requiring existing authenticated access rather than a remote exploit, limiting its standalone severity but making it a valuable pivot in multi-stage attack chains, including on engineering workstations that could host or interface with AI-driven design/simulation copilots or agentic automation tools—if such hosts run agent frameworks with stored credentials or API tokens, a successful local privilege escalation could expose those secrets to further compromise.
Affected Systems
Siemens IAM Client SDK as bundled in: COMOS V10.4.5 (<10.4.5.0.2), COMOS V10.6 (<10.6.1), Designcenter NX (<2512.7000), Simcenter 3D (<2512.7000), Simcenter Femap V2506 (<2506.0003), Simcenter Femap V2512 (<2512.0002), Simcenter Nastran (<2606), Simcenter STAR-CCM+ (<2606), Solid Edge SE2025 (<225.0.13.3), Solid Edge SE2026 (<226.0.04.003), Teamcenter Visualization V2412 (<2412.0012), V2506 (<2506.0009), V2512 (<2512.2605), Tecnomatix Plant Simulation V2404 (<2404.0022), V2504 (<2504.0010), Tecnomatix Process Simulate (<2606).
Indicators of Compromise
- No IOCs applicable — this is a vendor-disclosed vulnerability advisory, not an active exploitation campaign.
Remediation Steps
- 1
Apply vendor patches
Update each affected Siemens product to the fixed version specified by Siemens (e.g., COMOS V10.6.1+, Solid Edge SE2025 V225.0 Update 13+/SE2026 V226.0 Update 04+, Teamcenter Visualization, Simcenter, and Tecnomatix products to their respective fixed builds).
- 2
Contact Siemens for pending fixes
For COMOS V10.4.5, contact Siemens customer support to obtain the patch and update information since a public download is not yet available.
- 3
Restrict local access
Limit local logon rights and administrative privileges on engineering workstations running affected software to reduce the risk of local privilege escalation exploitation.
- 4
Network segmentation
Isolate ICS/engineering networks from business and internet-facing networks, and use firewalls per Siemens' operational guidelines for industrial security.
- 5
Secure remote access
If remote access is required, use up-to-date VPN solutions rather than direct exposure of control system devices.
CVE / Advisory IDs
Industries Most Exposed
Respond to this threat
Pro subscribers get a full AI-generated incident-response playbook for this threat — detection, containment, eradication, and recovery steps — plus an unlimited AI Threat Advisor for questions about your environment.