Full Report
Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available.
Analysis Summary
# Vulnerability: Unquoted Search Path in Siemens IAM Client
## CVE Details
- **CVE ID:** CVE-2025-40945
- **CVSS Score:** 6.7 (Medium) via CVSS v3.1 / 8.5 (High) via CVSS v4.0
- **CWE:** CWE-426: Untrusted Search Path (specifically involving unquoted paths in the IAM Client SDK)
## Affected Systems
- **Products:** Multiple Siemens PLM and Engineering software families using the IAM Client, including:
- **COMOS:** V10.4.5, V10.6
- **Designcenter NX**
- **Simcenter:** 3D, Femap (V2506, V2512), Nastran, STAR-CCM+
- **Solid Edge:** SE2025, SE2026
- **Teamcenter Visualization:** V2412, V2506, V2512
- **Tecnomatix:** Plant Simulation (V2404, V2504), Process Simulate
- **Versions:** See Remediation section for specific version cut-offs.
- **Configurations:** Systems where the affected software is installed and the IAM Client SDK service/component is active.
## Vulnerability Description
The IAM Client SDK component within these products contains an untrusted/unquoted search path vulnerability. When a service or application call is made to an executable or library where the file path contains spaces and is not enclosed in quotation marks, the Windows operating system may attempt to execute files in the parent directories that match the first part of the path name. An attacker can place a malicious executable in a higher-level directory to intercept the call.
## Exploitation
- **Status:** Not reported as exploited in the wild; advisory published July 2026.
- **Complexity:** Low
- **Attack Vector:** Local (Requires an authenticated local attacker)
## Impact
- **Confidentiality:** High (Full access to data accessible by the elevated process)
- **Integrity:** High (Ability to modify system files or application data)
- **Availability:** High (Ability to crash services or delete critical files)
## Remediation
### Patches
Siemens recommends updating to the following versions or later:
- **COMOS:** V10.4.5.0.2 / V10.6.1
- **Designcenter NX:** V2512.7000
- **Simcenter 3D:** V2512.7000
- **Simcenter Femap:** V2506.0003 / V2512.0002
- **Simcenter Nastran & STAR-CCM+:** V2606
- **Solid Edge:** SE2025 Update 13 / SE2026 Update 04
- **Teamcenter Visualization:** V2412.0012 / V2506.0009 / V2512.2605
- **Tecnomatix Plant Simulation:** V2404.0022 / V2504.0010
- **Tecnomatix Process Simulate:** V2606
### Workarounds
For products where fixes are not yet applied:
- Ensure strict file system permissions to prevent unprivileged users from writing files to root directories (e.g., `C:\`) or application parent folders.
- Limit local access to affected systems to trusted users only.
## Detection
- **Indicators of Compromise:** Presence of unexpected executable files (e.g., `program.exe` or `common.exe`) in root or parent directories of the Siemens installation.
- **Detection methods:** Audit service registry keys and shortcut paths for the IAM Client to identify paths containing spaces that lack surrounding quotation marks.
## References
- **Vendor Advisory:** hxxps://cert-portal.siemens.com/productcert/html/ssa-288252.html
- **Siemens ProductCERT:** hxxps://www.siemens.com/cert/advisories
- **Support Portal:** hxxps://support.sw.siemens.com/