
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40945 is an untrusted search path vulnerability (CWE-426) in the IAM Client SDK shared across multiple Siemens industrial and engineering software products. It allows an authenticated local user to potentially escalate privileges on affected systems. The vulnerability was published on July 14, 2026, and affects a broad range of Siemens products including COMOS, Designcenter NX, Simcenter 3D, Simcenter Femap, Simcenter Nastran, Simcenter STAR-CCM+, Solid Edge, Teamcenter Visualization, Tecnomatix Plant Simulation, and Tecnomatix Process Simulate. It carries a CVSS v3.1 base score of 6.7 (Medium) and a CVSS v4.0 base score of 8.5 (High) (GitHub Advisory, Siemens CERT).
The root cause is classified as CWE-426 (Untrusted Search Path), where the IAM Client SDK searches for critical resources using an externally-supplied or attacker-controllable search path. This allows a local authenticated attacker to place a malicious library or executable in a directory that the SDK searches before legitimate system paths, causing the application to load and execute attacker-controlled code. Exploitation requires local access and at minimum low-level user privileges, with no user interaction needed. The associated MITRE ATT&CK technique is T1574.007 (Path Interception by PATH Environment Variable) and CAPEC-38 (Leveraging/Manipulating Configuration File Search Paths) (GitHub Advisory, Siemens CERT).
Successful exploitation can result in full compromise of the vulnerable system's confidentiality, integrity, and availability, as the attacker can execute arbitrary code with elevated privileges. Because the IAM Client SDK is a shared component across many Siemens engineering and simulation products, the attack surface spans a wide range of industrial environments including manufacturing, process simulation, and product lifecycle management. Privilege escalation could enable an attacker to access sensitive engineering data, tamper with simulation or design files, or disrupt critical industrial workflows (GitHub Advisory).
There is no known public proof-of-concept exploit and no evidence of active in-the-wild exploitation as of the time of disclosure (Siemens CERT). The vulnerability is not listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, though CISA published an ICS advisory (ICSA-26-202-05) referencing this issue. The EPSS score is approximately 0.112% (2nd percentile), indicating a low near-term exploitation probability. Exploitation requires authenticated local access, which limits the attacker pool but remains a realistic threat in shared or multi-user industrial environments (GitHub Advisory).
comos.exe, solid_edge.exe, tcvis.exe) spawning unexpected child processes or loading DLLs from non-standard paths; use of tools like Process Monitor may reveal DLL load events from user-writable directories.Siemens has released patched versions for all affected products. Users should update to the following minimum versions: COMOS V10.4.5.0.2, COMOS V10.6.1, Designcenter NX V2512.7000, Simcenter 3D V2512.7000, Simcenter Femap V2506.0003 or V2512.0002, Simcenter Nastran V2606, Simcenter STAR-CCM+ V2606, Solid Edge SE2025 V225.0 Update 13, Solid Edge SE2026 V226.0 Update 04, Teamcenter Visualization V2412.0012 / V2506.0009 / V2512.2605, Tecnomatix Plant Simulation V2404.0022 or V2504.0010, and Tecnomatix Process Simulate V2606. As interim mitigations, restrict local access to systems running affected versions to authorized users only, and enforce strict file system permissions to prevent untrusted users from writing to application directories or modifying the PATH environment variable (Siemens CERT, GitHub Advisory).
Siemens published security advisory SSA-288252 on July 14, 2026, disclosing the vulnerability across its broad product portfolio. CISA also issued ICS advisory ICSA-26-202-05 in response to the disclosure, reflecting the relevance of this vulnerability to industrial control system environments (CISA ICS Advisory). No notable independent researcher commentary or significant social media discussion has been identified beyond standard vulnerability aggregator coverage.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."