Skip to content
SiemensCVE-2025-40945

Siemens COMOS: untrusted search path

High8.5CVE-2025-40945 · Published Jul 14, 2026 · updated Jul 15, 2026

A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter Nastran (All versions < V2606), Simcenter STAR-CCM+ (All versions < V2606), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Teamcenter Visualization V2412 (All versions < V2412.0012), Teamcenter Visualization V2506 (All versions < V2506.0009), Teamcenter Visualization V2512 (All versions < V2512.2605), Tecnomatix Plant Simulation V2404 (All versions < V2404.0022), Tecnomatix Plant Simulation V2504 (All versions < V2504.0010), Tecnomatix Process Simulate (All versions < V2606). Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access.

Siemens advisory

Affected versions

PackageAffectedFixed in
COMOS V10.4.5
Product
< V10.4.5.0.2V10.4.5.0.2
COMOS V10.6
Product
< V10.6.1V10.6.1
Designcenter NX
Product
< V2512.7000V2512.7000
Simcenter 3D
Product
< V2512.7000V2512.7000
Simcenter Femap V2506
Product
< V2506.0003V2506.0003
Simcenter Femap V2512
Product
< V2512.0002V2512.0002
Simcenter Nastran
Product
< V2606V2606
Simcenter STAR-CCM+
Product
< V2606V2606
Solid Edge SE2025
Product
< V225.0 Update 13V225.0 Update 13
Solid Edge SE2026
Product
< V226.0 Update 04V226.0 Update 04
Teamcenter Visualization V2412
Product
< V2412.0012V2412.0012
Teamcenter Visualization V2506
Product
< V2506.0009V2506.0009
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-426

More Siemens advisories

All Siemens
Advisory
Siemens SIMATIC S7-PLCSIM Advanced: denial of service
Medium6.0Jul 14
Siemens Opcenter X: authentication bypass
Critical10.0Jul 14
Siemens CPCI85 Central Processing/Communication: denial of service
High7.1Jul 9
Siemens CPCI85 Central Processing/Communication: code execution
High8.4Jul 9
Siemens CPCI85 Central Processing/Communication: insecure default
Medium6.3Jul 9
Siemens CPCI85 Central Processing/Communication: authenticated attacker could...
High8.6Jul 9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.