Description
A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter Nastran (All versions < V2606), Simcenter STAR-CCM+ (All versions < V2606), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Teamcenter Visualization V2412 (All versions < V2412.0012), Teamcenter Visualization V2506 (All versions < V2506.0009), Teamcenter Visualization V2512 (All versions < V2512.2605), Tecnomatix Plant Simulation V2404 (All versions < V2404.0022), Tecnomatix Plant Simulation V2504 (All versions < V2504.0010), Tecnomatix Process Simulate (All versions < V2606). Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access.
Published: 2026-07-14
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Siemens IAM Client SDK allows an authenticated user to manipulate the library search path used during runtime, enabling the loading of a malicious DLL from an untrusted location. This untrusted search path weakness (CWE‑426) can elevate the privileges of the executing user on the local machine, thereby compromising the confidentiality and integrity of project data within the affected Siemens engineering and simulation products. The vulnerability does not provide remote code execution; it requires local access and an authenticated account.

Affected Systems

All versions of the following Siemens products are vulnerable: COMOS V10.4.5 up to (but not including) V10.4.5.0.2, COMOS V10.6 up to (but not including) V10.6.1, Designcenter NX versions older than V2512.7000, Simcenter 3D older than V2512.7000, Simcenter Femap V2506 until V2506.0003, Simcenter Femap V2512 until V2512.0002, Simcenter Nastran and Simcenter STAR‑CCM+ below V2606, Solid Edge SE2025 before V225.0 Update 13, Solid Edge SE2026 before V226.0 Update 04, Teamcenter Visualization V2412 before V2412.0012, V2506 before V2506.0009, V2512 before V2512.2605, Tecnomatix Plant Simulation V2404 before V2404.0022, V2504 before V2504.0010, and Tecnomatix Process Simulate before V2606.

Risk and Exploitability

With a CVSS base score of 8.5, this local privilege escalation is considered high severity. The EPSS score of less than 1% indicates a very low, but still present, likelihood of exploitation in the wild, and the vulnerability is not listed in the CISA KEV catalog. The attack vector is local, requiring an authenticated user that can execute the SDK; once the search path is deceived to load a malicious library, the user’s privileges may be elevated on the host system.

Generated by OpenCVE AI on July 31, 2026 at 10:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade each affected Siemens product to a release that contains the IAM Client SDK fix addressing the untrusted search path vulnerability (see Siemens support or the product certificate reference for the specific version numbers).
  • Remove or restrict writable or untrusted directories from the system PATH and, where possible, configure the product to use a hardened, explicit search path.
  • Apply least‑privilege principles to any user accounts permitted to launch the SDK; limit local execution rights and monitor suspicious activity.

Generated by OpenCVE AI on July 31, 2026 at 10:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 31 Jul 2026 11:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation via Untrusted Search Path in Siemens IAM Client SDK

Sun, 26 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Untrusted Search Path in Siemens IAM Client SDK

Fri, 17 Jul 2026 23:00:00 +0000

Type Values Removed Values Added
Title Privilege Escalation via Untrusted Search Path in Siemens IAM Client SDK

Tue, 14 Jul 2026 13:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 14 Jul 2026 10:00:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter Nastran (All versions < V2606), Simcenter STAR-CCM+ (All versions < V2606), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Teamcenter Visualization V2412 (All versions < V2412.0012), Teamcenter Visualization V2506 (All versions < V2506.0009), Teamcenter Visualization V2512 (All versions < V2512.2605), Tecnomatix Plant Simulation V2404 (All versions < V2404.0022), Tecnomatix Plant Simulation V2504 (All versions < V2504.0010), Tecnomatix Process Simulate (All versions < V2606). Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access.
Weaknesses CWE-426
References
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-07-14T12:16:59.871Z

Reserved: 2025-04-16T09:06:15.879Z

Link: CVE-2025-40945

cve-icon Vulnrichment

Updated: 2026-07-14T12:16:55.649Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-07-31T10:45:04Z

Weaknesses