CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2025-40945

criticalCVSS 6.7covered by 3 sourcesfirst seen 2026-07-14
View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens IAM Client are affected: COMOS V10.4.5 vers:intdot/<10.4.5.0.2 COMOS V10.6 vers:intdot/<10.6.1 Designcenter NX vers:intdot/<2512.7000 Simcenter 3D vers:intdot/<2512.7000 Simcenter Femap V2506 vers:intdot/<2506.0003 Simcenter Femap V2512 vers:intdot/<2512.0002 Simcenter Nastran vers:intdot/<2606 Simcenter STAR-CCM+ vers:intdot/<2606 Solid Edge SE2025 vers:intdot/<225.0.13.3 Solid Edge SE2026 vers:intdot/<226.0.04.003 Teamcenter Visualization V2412 vers:intdot/<2412.0012 Teamcenter Visualization V2506 vers:intdot/<2506.0009 Teamcenter Visualization V2512 vers:intdot/<2512.2605 Tecnomatix Plant Simulation V2404 vers:intdot/<2404.0022 Tecnomatix Plant Simulation V2504 vers:intdot/<2504.0010 Tecnomatix Process Simulate vers:intdot/<2606 CVSS Vendor Equipment Vulnerabilities v3 6.7 Siemens Siemens IAM Client Untrusted Search Path Background Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2025-40945 Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access. View CVE Details Affected Products Siemens IAM Client Vendor: Siemens Product Version: COMOS V10.4.5 < V10.4.5.0.2, COMOS V10.6 < V10.6.1, Designcenter NX < V2512.7000, Simcenter 3D < V2512.7000, Simcenter Femap V2506 < V2506.0003, Simcenter Femap V2512 < V2512.0002, Simcenter Nastran < V2606, Simcenter STAR-CCM+ < V2606, Solid Edge SE2025 < V225.0.13.3,

CSIRTS triage

vendor: Siemensproduct: IAM ClientPrivilege escalationaffected: COMOS V10.4.5 vers:intdot/<10.4.5.0.2, COMOS V10.6 vers:intdot/<10.6.1, Designcenter NX vers:intdot/<2512.7000, Simcenter 3D vers:intdot/<2512.7000, Simcenter Femap V2506 vers:intdot/<2506.0003, Simce
What
An unquoted search path vulnerability could allow privilege escalation.
Who is affected
Deployments of affected versions of IAM Client.
Urgency
Critical remediation is necessary due to the potential for privilege escalation.
Action
Update to the latest versions of IAM Client.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2025-40945

Get an email if CVE-2025-40945 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (3)

External references

NVD record for CVE-2025-40945

CVE.org record

Embed the live status

CVE-2025-40945 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2025-40945 status](https://www.csirts.com/badge/CVE-2025-40945)](https://www.csirts.com/cve/CVE-2025-40945)