Full Report
Simcenter STAR-CCM+ contains an information disclosure vulnerability when using the Power-on-Demand public license server. An attacker could access a system’s host, user, and display name. Siemens has updated the public Power-on-Demand public license server.
Analysis Summary
# Vulnerability: Information Disclosure in Simcenter STAR-CCM+ License Server
## CVE Details
- **CVE ID:** CVE-2022-34659
- **CVSS Score:**
- CVSS v4.0: **6.9** (Medium)
- CVSS v3.1: **5.3** (Medium)
- **CWE:** CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor)
## Affected Systems
- **Products:** Simcenter STAR-CCM+ (Multiphysics CFD software)
- **Versions:** All versions
- **Configurations:** Only vulnerable when configured to use the **Power-on-Demand public license server**.
## Vulnerability Description
Simcenter STAR-CCM+ transmits metadata to the public Power-on-Demand license server during the license validation process. Due to this flaw, the application exposes the **host name**, **user name**, and **display name** of the system running the software. An unauthorized actor could intercept or access this information via the public license server infrastructure, leading to the disclosure of internal naming conventions and potential user identities.
## Exploitation
- **Status:** Not exploited (No reports of active exploitation or public PoC provided in the advisory).
- **Complexity:** Low
- **Attack Vector:** Network (Remote)
## Impact
- **Confidentiality:** Low (Access to system and user metadata)
- **Integrity:** None
- **Availability:** None
## Remediation
### Patches
- **Server-Side Fix:** Siemens updated the public Power-on-Demand license server on **2026-06-24**.
- **User Action:** No manual software update is required for the client application to benefit from the server-side fix.
### Workarounds
If users wish to further anonymize their data or mitigate risks in environments where server-side updates cannot be verified:
- **Environment Variable:** Set `STARLICENSEHIDE=1`. This causes the software to send the string "unknown" for the user, host, and display names. This mitigation is supported in all versions since V8.04 (June 2013).
- **Naming Conventions:** Avoid using sensitive, proprietary, or personal data in system hostnames or user account names.
## Detection
- **Indicators of Compromise:** Unusual network traffic directed toward the public license server containing cleartext system metadata.
- **Detection Methods:** Audit environment variables on workstations to ensure `STARLICENSEHIDE` is active if high-privacy mode is required. Monitor outbound traffic to Siemens licensing endpoints.
## References
- **Vendor Advisory:** hxxps://cert-portal[.]siemens[.]com/productcert/html/ssa-555707[.]html
- **Siemens Industrial Security Guidelines:** hxxps://www[.]siemens[.]com/cert/operational-guidelines-industrial-security