CVE-2025-40945
View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens IAM Client are affected: COMOS V10.4.5 vers:intdot/<10.4.5.0.2 COMOS V10.6 vers:intdot/<10.6.1 Designcenter NX vers:intdot/<2512.7000 Simcenter 3D vers:intdot/<2512.7000 Simcenter Femap V2506 vers:intdot/<2506.0003 Simcenter Femap V2512 vers:intdot/<2512.0002 Simcenter Nastran vers:intdot/<2606 Simcenter STAR-CCM+ vers:intdot/<2606 Solid Edge SE2025 vers:intdot/<225.0.13.3 Solid Edge SE2026 vers:intdot/<226.0.04.003 Teamcenter Visualization V2412 vers:intdot/<2412.0012 Teamcenter Visualization V2506 vers:intdot/<2506.0009 Teamcenter Visualization V2512 vers:intdot/<2512.2605 Tecnomatix Plant Simulation V2404 vers:intdot/<2404.0022 Tecnomatix Plant Simulation V2504 vers:intdot/<2504.0010 Tecnomatix Process Simulate vers:intdot/<2606 CVSS Vendor Equipment Vulnerabilities v3 6.7 Siemens Siemens IAM Client Untrusted Search Path Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2025-40945 Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access. View CVE Details Affected Products Siemens IAM Client Vendor: Siemens Product Version: COMOS V10.4.5 < V10.4.5.0.2, COMOS V10.6 < V10.6.1, Designcenter NX < V2512.7000, Simcenter 3D < V2512.7000, Simcenter Femap V2506 < V2506.0003, Simcenter Femap V2512 < V2512.0002, Simcenter Nastran < V2606, Simcenter STAR-CCM+ < V2606, Solid Edge SE2025 < V225.0.13.3,
CSIRTS triage
- What
- An unquoted search path vulnerability could allow privilege escalation.
- Who is affected
- Deployments of affected versions of IAM Client.
- Urgency
- Critical remediation is necessary due to the potential for privilege escalation.
- Action
- Update to the latest versions of IAM Client.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2025-40945
Get an email if CVE-2025-40945 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Advisory coverage (3)
- criticalSiemens IAM Clientcisa · 2026-07-21
- unknownNCSC-2026-0229 [1.00] [M/H] Vulnerabilities fixed in Siemens productsncsc-nl · 2026-07-14
- mediumCVE-2025-40945: A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6…nvd · 2026-07-14
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2025-40945)