CVE-2025-40945: High severity Siemens COMOS vulnerability
A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter Nastran (All versions < V2606), Simcenter STAR-CCM+ (All versions < V2606), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Teamcenter Visualization V2412 (All versions < V2412.0012), Teamcenter Visualization V2506 (All versions < V2506.0009), Teamcenter Visualization V2512 (All versions < V2512.2605), Tecnomatix Plant Simulation V2404 (All versions < V2404.0022), Tecnomatix Plant Simulation V2504 (All versions < V2504.0010), Tecnomatix Process Simulate (All versions < V2606). Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40945?
The severity of CVE-2025-40945 is medium, rated at 6.7.
How do I fix CVE-2025-40945?
To fix CVE-2025-40945, update your software to the latest versions specified in the advisory.
What systems are affected by CVE-2025-40945?
CVE-2025-40945 affects various Siemens software, including COMOS, Designcenter NX, Simcenter 3D, and Simcenter Femap.
What are the potential impacts of CVE-2025-40945?
CVE-2025-40945 can lead to high confidentiality, integrity, and availability risks due to the vulnerabilities in the affected software.
Is there a workaround for CVE-2025-40945?
Currently, there is no established workaround for CVE-2025-40945; the best approach is to apply the recommended software updates.