Privilege escalation through an untrusted search path in Siemens IAM Client SDK

Note: This data is for reference and cybersecurity research purposes only.CyStack advises users not to use this information for unlawful purposes.

What is CVE-2025-40945?

CVE-2025-40945 is a vulnerability classified as Untrusted Search Path, affecting COMOS V10.4.5 (affected versions: < V10.4.5.0.2), COMOS V10.6 (affected versions: < V10.6.1), Designcenter NX (affected versions: < V2512.7000), and 13 more products. This vulnerability is rated High, with a CVSS score of 8.5. Current sources do not report this vulnerability as exploited.

Overview

Original source data

A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter Nastran (All versions < V2606), Simcenter STAR-CCM+ (All versions < V2606), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Teamcenter Visualization V2412 (All versions < V2412.0012), Teamcenter Visualization V2506 (All versions < V2506.0009), Teamcenter Visualization V2512 (All versions < V2512.2605), Tecnomatix Plant Simulation V2404 (All versions < V2404.0022), Tecnomatix Plant Simulation V2504 (All versions < V2504.0010), Tecnomatix Process Simulate (All versions < V2606). Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access.

Affected products and scope

Siemens identifies the following affected ranges:

  • COMOS V10.4.5: all versions < V10.4.5.0.2.
  • COMOS V10.6: all versions < V10.6.1.
  • Designcenter NX: all versions < V2512.7000.
  • Simcenter 3D: all versions < V2512.7000.
  • Simcenter Femap V2506: all versions < V2506.0003.
  • Simcenter Femap V2512: all versions < V2512.0002.
  • Simcenter Nastran: all versions < V2606.
  • Simcenter STAR-CCM+: all versions < V2606.
  • Solid Edge SE2025: all versions < V225.0 Update 13.
  • Solid Edge SE2026: all versions < V226.0 Update 04.
  • Teamcenter Visualization V2412: all versions < V2412.0012.
  • Teamcenter Visualization V2506: all versions < V2506.0009.
  • Teamcenter Visualization V2512: all versions < V2512.2605.
  • Tecnomatix Plant Simulation V2404: all versions < V2404.0022.
  • Tecnomatix Plant Simulation V2504: all versions < V2504.0010.
  • Tecnomatix Process Simulate: all versions < V2606.

The record does not establish the status of unlisted branches or variants outside these ranges. A parallel branch should not be assumed unaffected merely because another branch has a fix.

Technical details

The issue is CWE-426: Untrusted Search Path in the IAM Client SDK integrated into the affected Siemens products. The component may use an untrusted search path when locating and loading a dependency; Siemens does not disclose the exact search order, file type, filename, or loading context. An attacker needs an authenticated account and local access to a system where an affected product is installed. The supplied record indicates that no user interaction is required and that attack complexity is low. If a highly privileged process loads a component from an attacker-controlled location, the condition could enable privilege escalation, but the implementation details needed to achieve that outcome are not public.

Exploitability

  • Reachability: Exploitation requires local access to a host running an affected product.
  • Authentication: The attacker must be authenticated.
  • User interaction: The record indicates that no user interaction is required.
  • Complexity: The structured record describes the attack complexity as low.
  • Exploitation status: The record marks public exploit as false. No campaign, victim, breach, or specific exploitation evidence is identified in the supplied data, and known-exploited status is not established.

Technical impact

The flaw may allow an authenticated user with local access to elevate privileges on the same host. The technical outcome may include access to data the original account could not read, modification of data or configuration, and an effect on system availability, depending on the privileges of the affected process. The stated impact is local, with no downstream system impact established by the record. The record does not provide enough detail to confirm code execution, remote access, authentication bypass, or impact to other hosts.

Business impact

  • A locally authenticated user on an affected host may cross a privilege boundary if exploitation succeeds.
  • Higher privileges could permit access to or modification of design data, models, configuration, and files handled by the product, depending on the privileges of the affected process.
  • The availability of a workstation or server running the software could also be affected if elevated access permits local components to be changed or disrupted.
  • Actual risk depends on the installed product, the privileges of the IAM Client process, and the local permissions held by the authenticated account. The record does not confirm a breach, data loss, or specific operational disruption.

Remediation

  1. Prioritize branch-specific updates:
  • Update COMOS V10.4.5 to V10.4.5.0.2. Siemens instructs customers to contact support for patch and update information.
  • Update COMOS V10.6 to V10.6.1.
  • Update Designcenter NX to V2512.7000.
  • Update Simcenter 3D to V2512.7000.
  • Update Simcenter Femap V2506 to V2506.0003.
  • Update Simcenter Femap V2512 to V2512.0002.
  • Update Simcenter Nastran to V2606.
  • Update Simcenter STAR-CCM+ to V2606.
  • Update Solid Edge SE2025 to V225.0 Update 13.
  • Update Solid Edge SE2026 to V226.0 Update 04.
  • Update Teamcenter Visualization V2412 to V2412.0012.
  • Update Teamcenter Visualization V2506 to V2506.0009.
  • Update Teamcenter Visualization V2512 to V2512.2605.
  • Update Tecnomatix Plant Simulation V2404 to V2404.0022.
  • Update Tecnomatix Plant Simulation V2504 to V2504.0010.
  • Update Tecnomatix Process Simulate to V2606.
  1. After updating, verify the installed version on every host and confirm that the IAM Client SDK was updated with the product. Do not use a fix for one product or branch to conclude that other products or branches are remediated.
  2. Until updates can be applied, restrict local access to affected hosts as necessary and allow use only by trusted accounts. This is a temporary defense-in-depth measure, not a replacement for the Siemens update.
  3. Apply Siemens recommendations for protecting the operating environment and network. The record does not provide a universal workaround that completely removes the search-path weakness.

Detection

  1. Inventory workstations and servers running COMOS, Designcenter NX, Simcenter, Solid Edge, Teamcenter Visualization, or Tecnomatix, and identify installations that include the IAM Client SDK.
  2. Compare the installed product versions with the boundaries in affected_summary. Versions below the applicable boundary should be treated as requiring remediation.
  3. Review update history and deployment evidence to confirm that the fix was applied to the correct product branch, rather than checking only one representative Siemens product.
  4. As a precaution, review endpoint telemetry for affected product processes loading files or components from unexpected search-path locations. Siemens does not publish a dedicated log event, exact path, or IOC for this issue, so the absence of such log evidence must not be treated as proof of safety.
Sources (17)
Learn more

Run an in-depth assessment with complete web risk management

CyStack VulnScan continuously discovers assets, validates vulnerabilities, and helps security teams prioritize remediation across the organization.

Explore CyStack VulnScan