CVE-2025-40945
Siemens Tecnomatix Plant Simulation vulnerability analysis and mitigation

Overview

CVE-2025-40945 is an untrusted search path vulnerability (CWE-426) in the IAM Client SDK shared across multiple Siemens industrial software products that may allow an authenticated user to escalate privileges via local access. Disclosed on July 14, 2026, it affects a broad range of Siemens products including COMOS, Designcenter NX, Simcenter 3D, Simcenter Femap, Simcenter Nastran, Simcenter STAR-CCM+, Solid Edge SE2025/SE2026, Teamcenter Visualization, Tecnomatix Plant Simulation, and Tecnomatix Process Simulate. The vulnerability carries a CVSS v3.1 base score of 6.7 (Medium) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, Siemens Advisory).

Technical details

The root cause is an untrusted search path (CWE-426) in the IAM Client SDK, where the software searches for critical resources using an externally-supplied or attacker-controllable search path. This maps to CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) and MITRE ATT&CK technique T1574.007 (Path Interception by PATH Environment Variable). An authenticated local user can place a malicious library or executable in a directory that the IAM Client SDK searches before the legitimate resource location, causing the application to load and execute attacker-controlled code. Exploitation requires local access and at least low-level privileges, with no user interaction needed (GitHub Advisory, Siemens Advisory).

Impact

Successful exploitation can result in full compromise of the vulnerable system's confidentiality, integrity, and availability, as the attacker can execute arbitrary code with elevated privileges. Because the affected products are widely used in industrial design, simulation, and manufacturing environments, a privilege escalation could enable an attacker to access sensitive engineering data, tamper with simulation or plant models, or disrupt critical operational workflows. The scope of impact is limited to the vulnerable system itself (no subsequent system impact per CVSS v4.0 metrics), but lateral movement within an industrial network remains a risk if the compromised account has broader access (GitHub Advisory, Siemens Advisory).

Exploitation steps

  1. Gain local access: Obtain authenticated local access to a system running one of the affected Siemens products (e.g., via insider access, phishing, or prior compromise).
  2. Identify the IAM Client SDK search path: Enumerate the directories searched by the IAM Client SDK for DLLs or executables, using tools such as Process Monitor (Windows) or strace/ltrace (Linux) to observe file system lookups during application startup.
  3. Identify a writable directory in the search path: Locate a directory earlier in the search order that the current user has write access to (e.g., the application's working directory, a user-writable PATH entry, or a temp directory).
  4. Plant a malicious binary: Place a crafted DLL or executable with the same name as a legitimate resource expected by the IAM Client SDK into the writable directory.
  5. Trigger application execution: Launch or cause the affected Siemens application to start, prompting the IAM Client SDK to load the malicious binary from the attacker-controlled path.
  6. Achieve privilege escalation: The malicious code executes in the context of the application's elevated process, granting the attacker higher privileges on the system (GitHub Advisory, Siemens Advisory).

Indicators of compromise

  • File System: Unexpected DLL or executable files placed in the application's working directory, installation directory subdirectories, or user-writable PATH locations with names matching legitimate IAM Client SDK components; recently modified files in Siemens product installation directories by non-administrative accounts.
  • Process: Siemens application processes (e.g., COMOS, Solid Edge, Teamcenter Visualization) spawning unexpected child processes or loading DLLs from non-standard paths; use of Process Monitor or similar tools may reveal DLL load events from user-writable directories.
  • Logs: Windows Event Logs showing process creation events with elevated privileges originating from Siemens application processes; application event logs recording unexpected module load failures or successes from atypical paths.
  • Network: Outbound connections from Siemens engineering workstations to unknown external hosts following application startup, potentially indicating post-exploitation activity.

Mitigation and workarounds

Siemens has released patched versions for all affected products. Organizations should update to the following minimum versions: COMOS V10.4.5.0.2, COMOS V10.6.1, Designcenter NX V2512.7000, Simcenter 3D V2512.7000, Simcenter Femap V2506.0003 or V2512.0002, Simcenter Nastran V2606, Simcenter STAR-CCM+ V2606, Solid Edge SE2025 V225.0 Update 13, Solid Edge SE2026 V226.0 Update 04, Teamcenter Visualization V2412.0012/V2506.0009/V2512.2605, Tecnomatix Plant Simulation V2404.0022 or V2504.0010, and Tecnomatix Process Simulate V2606. As interim workarounds, restrict local system access to authorized users only and enforce strict file system permissions to prevent untrusted users from writing to directories in the application's search path (Siemens Advisory, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Siemens Tecnomatix Plant Simulation vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-40801CRITICAL9.2
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:simcenter_femap
NoYesDec 09, 2025
CVE-2025-40945HIGH8.5
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:tecnomatix_plant_simulation
NoYesJul 14, 2026
CVE-2025-32454HIGH7.3
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:tecnomatix_plant_simulation
NoYesMay 13, 2025
CVE-2025-27438HIGH7.3
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:tecnomatix_plant_simulation
NoYesMar 11, 2025
CVE-2025-40745MEDIUM6.3
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:simcenter_femap
NoYesApr 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management