Security & Threat Intelligence · 21.07.2026, 21:21 UTC
Siemens IAM Client
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA Advisories · CISA ICS Advisories ↗ |
| Veröffentlicht | 21.07.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2025-40945. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. The following versions of Siemens IAM Client are affected:
COMOS V10.4.5 vers:intdot/<10.4.5.0.2 COMOS V10.6 vers:intdot/<10.6.1 Designcenter NX vers:intdot/<2512.7000 Simcenter 3D vers:intdot/<2512.7000 Simcenter Femap V2506 vers:intdot/<2506.0003 Simcenter Femap V2512 vers:intdot/<2512.0002 Simcenter Nastran vers:intdot/<2606 Simcenter STAR-CCM+ vers:intdot/<2606 Solid Edge SE2025 vers:intdot/<225.0.13.3 Solid Edge SE2026 vers:intdot/<226.0.04.003 Teamcenter Visualization V2412 vers:intdot/<2412.0012 Teamcenter Visualization V2506 vers:intdot/<2506.0009 Teamcenter Visualization V2512 vers:intdot/<2512.2605 Tecnomatix Plant Simulation V2404 vers:intdot/<2404.0022 Tecnomatix Plant Simulation V2504 vers:intdot/<2504.0010 Tecnomatix Process Simulate vers:intdot/<2606
CVSS Vendor Equipment Vulnerabilities
v3 6.7 Siemens Siemens IAM Client Untrusted Search Path
Background
Critical Infrastructure Sectors: Chemical, Critical Manufacturing, Energy Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2025-40945
Untrusted search path in IAM Client SDK may allow an authenticated …