
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40945 is an untrusted search path vulnerability (CWE-426) in the IAM Client SDK shared across multiple Siemens industrial software products that may allow an authenticated user to escalate privileges via local access. Disclosed on July 14, 2026, it affects a broad range of Siemens products including COMOS, Designcenter NX, Simcenter 3D, Simcenter Femap, Simcenter Nastran, Simcenter STAR-CCM+, Solid Edge SE2025/SE2026, Teamcenter Visualization, Tecnomatix Plant Simulation, and Tecnomatix Process Simulate. The vulnerability carries a CVSS v3.1 base score of 6.7 (Medium) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, Siemens Advisory).
The root cause is an untrusted search path (CWE-426) in the IAM Client SDK, where the software searches for critical resources using an externally-supplied or attacker-controllable search path. This maps to CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) and MITRE ATT&CK technique T1574.007 (Path Interception by PATH Environment Variable). An authenticated local user can place a malicious library or executable in a directory that the IAM Client SDK searches before the legitimate resource location, causing the application to load and execute attacker-controlled code. Exploitation requires local access and at least low-level privileges, with no user interaction needed (GitHub Advisory, Siemens Advisory).
Successful exploitation can result in full compromise of the vulnerable system's confidentiality, integrity, and availability, as the attacker can execute arbitrary code with elevated privileges. Because the affected products are widely used in industrial design, simulation, and manufacturing environments, a privilege escalation could enable an attacker to access sensitive engineering data, tamper with simulation or plant models, or disrupt critical operational workflows. The scope of impact is limited to the vulnerable system itself (no subsequent system impact per CVSS v4.0 metrics), but lateral movement within an industrial network remains a risk if the compromised account has broader access (GitHub Advisory, Siemens Advisory).
strace/ltrace (Linux) to observe file system lookups during application startup.Siemens has released patched versions for all affected products. Organizations should update to the following minimum versions: COMOS V10.4.5.0.2, COMOS V10.6.1, Designcenter NX V2512.7000, Simcenter 3D V2512.7000, Simcenter Femap V2506.0003 or V2512.0002, Simcenter Nastran V2606, Simcenter STAR-CCM+ V2606, Solid Edge SE2025 V225.0 Update 13, Solid Edge SE2026 V226.0 Update 04, Teamcenter Visualization V2412.0012/V2506.0009/V2512.2605, Tecnomatix Plant Simulation V2404.0022 or V2504.0010, and Tecnomatix Process Simulate V2606. As interim workarounds, restrict local system access to authorized users only and enforce strict file system permissions to prevent untrusted users from writing to directories in the application's search path (Siemens Advisory, GitHub Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."