BetaIT-Hub is in early access — your feedback helps us improve. Use the chat or email [email protected]

News Vulnerability
VulnerabilityCISA·7d ago

Siemens IAM Client

p a href="https://github.com/cisagov/CSAF/blob/develop/csaf_files/OT/white/2026/icsa-26-202-05.json" strong View CSAF /strong /a /p h2 Summary /h2 p strong Multiple Siemens products are affected by unquoted search path vulnerability in IAM Client. This could allow an authenticated local attacker to perform privilege escalation. Siemens has released new versions for several affected products and recommends to update to the latest versions. Siemens is preparing further fix versions and recommends countermeasures for products where fixes are not, or not yet available. /strong /p p The following versions of Siemens IAM Client are affected: /p ul li COMOS V10.4.5 vers:intdot/ lt;10.4.5.0.2 nbsp; /li li COMOS V10.6 vers:intdot/ lt;10.6.1 nbsp; /li li Designcenter NX vers:intdot/ lt;2512.7000 nbsp; /li li Simcenter 3D vers:intdot/ lt;2512.7000 nbsp; /li li Simcenter Femap V2506 vers:intdot/ lt;2506.0003 nbsp; /li li Simcenter Femap V2512 vers:intdot/ lt;2512.0002 nbsp; /li li Simcenter Nastran vers:intdot/ lt;2606 nbsp; /li li Simcenter STAR-CCM+ vers:intdot/ lt;2606 nbsp; /li li Solid Edge SE2025 vers:intdot/ lt;225.0.13.3 nbsp; /li li Solid Edge SE2026 vers:intdot/ lt;226.0.04.003 nbsp; /li li Teamcenter Visualization V2412 vers:intdot/ lt;2412.0012 nbsp; /li li Teamcenter Visualization V2506 vers:intdot/ lt;2506.0009 nbsp; /li li Teamcenter Visualization V2512 vers:intdot/ lt;2512.2605 nbsp; /li li Tecnomatix Plant Simulation V2404 vers:intdot/ lt;2404.0022 nbsp; /li li Tecnomatix Plant Simulation V2504 vers:intdot/ lt;2504.0010 nbsp; /li li Tecnomatix Process Simulate vers:intdot/ lt;2606 nbsp; /li /ul div class="csaf-table" table class="tablesaw tablesaw-stack" data-tablesaw-mode="stack" data-tablesaw-minimap thead tr th role="columnheader" data-tablesaw-priority="persist" CVSS /th th role="columnheader" Vendor /th th role="columnheader" Equipment /th th role="columnheader" Vulnerabilities /th /tr /thead tbody tr td v3 6.7 /td td Siemens /td td Siemens IAM Client /td td Untrusted Search Path /td /tr /tbody /table /div h3 Background /h3 ul li strong Critical Infrastructure Sectors: /strong Chemical, Critical Manufacturing, Energy /li li strong Countries/Areas Deployed: /strong Worldwide /li li strong Company Headquarters Location: /strong Germany /li /ul hr h2 Vulnerabilities /h2 div class="csaf-accordion" p a class="csaf-accordion-toggle-all" href="#" Expand All + /a /p div class="csaf-accordion-item" h3 a class="csaf-accordion-toggle" href="#" CVE-2025-40945 /a /h3 div class="csaf-accordion-content" p Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access. /p p a href="https://www.cve.org/CVERecord?id=CVE-2025-40945" View CVE Details /a /p hr h4 Affected Products /h4 h5 Siemens IAM Client /h5 div class="ics-vendor-version-status" div class="ics-vendor" strong Vendor: /strong br Siemens /div div class="ics-version" strong Product Version: /strong br COMOS V10.4.5 lt; V1

Sign in to read the full article

Create a free account to access all news, downloads, and community features

Originally published by CISA

Source: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-05

This article is shared for informational purposes. All rights belong to the original author and publisher. If you are the copyright holder and would like this content removed, please contact us.

Shared on IT-Hub by admin