CVE-2025-40945 Details
Description
A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter Nastran (All versions < V2606), Simcenter STAR-CCM+ (All versions < V2606), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Teamcenter Visualization V2412 (All versions < V2412.0012), Teamcenter Visualization V2506 (All versions < V2506.0009), Teamcenter Visualization V2512 (All versions < V2512.2605), Tecnomatix Plant Simulation V2404 (All versions < V2404.0022), Tecnomatix Plant Simulation V2504 (All versions < V2504.0010), Tecnomatix Process Simulate (All versions < V2606). Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access.
A vulnerability exists in multiple Siemens products, including COMOS, Designcenter NX, Simcenter applications, Solid Edge, Teamcenter Visualization, and Tecnomatix tools. This vulnerability, present in various versions prior to specific updates, involves an untrusted search path in the IAM Client SDK. It may allow an authenticated user to escalate privileges through local access.
Siemens has released patches for many affected products. Users should update to the latest versions. For products where a patch is not yet available, Siemens recommends following general security guidelines and consulting the Siemens ProductCERT for further assistance.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 14, 2026CISA-ADP
Assessed Jul 14, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://cert-portal.siemens.com/productcert/html/ssa-288252.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-426 | Untrusted Search Path | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Siemens COMOS | < V10.4.5.0.2 |
CPE
Remediation
| |
| Siemens Designcenter NX | < V2512.7000 |
CPE
Remediation
| |
| Siemens Simcenter 3D | < V2512.7000 |
CPE
Remediation
| |
| Siemens Simcenter Femap | < V2506.0003 < V2512.0002 |
CPE
Remediation
| |
| Siemens Simcenter Nastran | < V2606 |
CPE
Remediation
| |
| Siemens Simcenter STAR-CCM+ | < V2606 |
CPE
Remediation
| |
| Siemens Solid Edge | < V225.0 Update 13 < V226.0 Update 04 |
CPE
Remediation
| |
| Siemens Teamcenter Visualization | < V2412.0012 < V2506.0009 < V2512.2605 |
CPE
Remediation
| |
| Siemens Tecnomatix Plant Simulation | < V2404.0022 < V2504.0010 |
CPE
Remediation
| |
| Siemens Tecnomatix Process Simulate | < V2606 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 14, 2026 | CVE Modified | CISA-ADP |
| Jul 14, 2026 | New CVE Received | [email protected] |
Volerion