CISA flags Siemens IAM Client privilege-escalation flaw
A medium CVSS score still matters when the vulnerable client sits inside engineering and simulation workflows defense suppliers already trust.
TL;DR
The Cybersecurity and Infrastructure Security Agency republished Siemens ProductCERT SSA-288252 for CVE-2025-40945, a CVSS 6.7 untrusted search path flaw in Siemens IAM Client. The advisory lists 16 affected Siemens products, including COMOS, Designcenter NX, Simcenter, Solid Edge, Teamcenter Visualization and Tecnomatix. Primes, subs and defense-industrial-base operators using those tools in industrial environments should plan coordinated updates, especially where Siemens lists fixes for some products and further fix versions or countermeasures for others.
CVE-2025-40945 is not the loudest industrial-control-system advisory CISA will publish this month. It is local, requires an authenticated user and carries a CVSS v3.1 score of 6.7. That is also why it is easy to under-rank. The affected component is Siemens IAM Client, and the product list is not a stray utility on a lab workstation: COMOS, Designcenter NX, Simcenter 3D, Simcenter Femap, Simcenter Nastran, Simcenter STAR-CCM+, Solid Edge, Teamcenter Visualization and Tecnomatix all appear in the advisory.
The Cybersecurity and Infrastructure Security Agency says the untrusted search path in the IAM Client SDK may allow an authenticated user with local access to escalate privileges. Siemens has released updated versions for several affected products and recommends moving to the latest versions. The advisory also says Siemens is preparing further fix versions and recommends countermeasures where fixes are not, or not yet, available. That leaves the usual industrial problem: the patch may be clear, but the maintenance window may not be.
For defense primes, subs and other operators running these tools in chemical, critical manufacturing or energy environments, the practical issue is not internet exposure. It is the assumption that a user who can log into an engineering, visualization or simulation workstation cannot turn that foothold into broader control just because the account is not an administrator. Unquoted or untrusted search path bugs are old. They still matter because design and operations environments often give authenticated users access to machines that sit closer to production data, plant models and operational workflows than the corporate security diagram admits.
Monday's work is inventory first, patch second and compensating control review in parallel. Teams should identify affected Siemens versions, prioritize engineering workstations and shared systems, and align updates with production constraints rather than treating this as a generic endpoint patch. Where Siemens has not yet supplied a fix for a deployed product line, the risk decision should be explicit: who has local access, what can run on those hosts, and whether segmentation between engineering systems and OT assets is real or just documented.
Published ·Deep Fathom