VYPR
advisoryPublished Jul 21, 2026· 1 source

Siemens IAM Client Vulnerable to Privilege Escalation via Unquoted Search Path

CISA has alerted users to a critical vulnerability in Siemens IAM Client, CVE-2025-40945, which could allow local attackers to escalate privileges.

Siemens' Identity and Access Management (IAM) Client software contains a critical vulnerability, identified as CVE-2025-40945, that could permit an authenticated local attacker to escalate their privileges on affected systems. The vulnerability stems from an "unquoted search path" flaw within the IAM Client SDK, a common type of weakness where the system's operating environment may inadvertently execute malicious code if it resides in a directory whose name contains spaces and is listed in the system's PATH environment variable.

This flaw impacts a wide array of Siemens products, including those used in industrial automation and engineering design. Affected software includes various versions of COMOS, Designcenter NX, Simcenter 3D, Simcenter Femap, Simcenter Nastran, Simcenter STAR-CCM+, Solid Edge, Teamcenter Visualization, Tecnomatix Plant Simulation, and Tecnomatix Process Simulate. The extensive reach of these products across critical manufacturing, chemical, and energy sectors highlights the potential impact of this vulnerability.

An attacker who gains initial local access to an affected system could exploit this vulnerability. By placing a malicious executable in a specific location that the IAM Client searches, the attacker could trick the software into running their code with elevated privileges. This could lead to a full system compromise, allowing the attacker to install malware, steal sensitive data, or disrupt operations.

Siemens has acknowledged the vulnerability and has begun releasing updated versions for many of the affected products. Users are strongly advised to update to the latest available versions as soon as possible. For products where fixes are not yet available, Siemens recommends implementing specific countermeasures to mitigate the risk, though details on these countermeasures are not provided in the advisory.

The Common Vulnerabilities and Exposures (CVE) system has assigned CVE-2025-40945 to this issue. The vulnerability carries a CVSS v3.1 base score of 6.7, classified as Medium severity. While this score might seem moderate, the potential for privilege escalation in industrial control systems or critical infrastructure environments can have severe consequences, making timely patching and mitigation crucial.

CISA has included this vulnerability in its ICS Advisories, underscoring its importance for the operational technology (OT) landscape. The advisory emphasizes general security recommendations for industrial control systems, including minimizing network exposure, isolating control system networks from business networks, and using secure remote access methods like VPNs. Organizations are urged to perform thorough impact analyses and risk assessments before deploying any defensive measures.

This incident serves as a reminder of the ongoing security challenges within the industrial sector, where complex software suites often have intricate dependencies and potential vulnerabilities. The broad impact across multiple Siemens product lines underscores the need for diligent patch management and continuous security monitoring within OT environments.

Synthesized by Vypr AI