CVE-2025-40945

MEDIUM

Siemens Comos V10.4.5 - Untrusted Search Path

Title source: rule
STIX 2.1

Description

A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter Nastran (All versions < V2606), Simcenter STAR-CCM+ (All versions < V2606), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Teamcenter Visualization V2412 (All versions < V2412.0012), Teamcenter Visualization V2506 (All versions < V2506.0009), Teamcenter Visualization V2512 (All versions < V2512.2605), Tecnomatix Plant Simulation V2404 (All versions < V2404.0022), Tecnomatix Plant Simulation V2504 (All versions < V2504.0010), Tecnomatix Process Simulate (All versions < V2606). Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access.

Scores

CVSS v3 6.7
EPSS 0.0011
EPSS Percentile 1.6%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-426
Status published
Products (16)
Siemens/COMOS V10.4.5 < V10.4.5.0.2
Siemens/COMOS V10.6 < V10.6.1
Siemens/Designcenter NX < V2512.7000
Siemens/Simcenter 3D < V2512.7000
Siemens/Simcenter Femap V2506 < V2506.0003
Siemens/Simcenter Femap V2512 < V2512.0002
Siemens/Simcenter Nastran < V2606
Siemens/Simcenter STAR-CCM+ < V2606
Siemens/Solid Edge SE2025 < V225.0 Update 13
Siemens/Solid Edge SE2026 < V226.0 Update 04
... and 6 more
Published Jul 14, 2026
Tracked Since Jul 14, 2026