news.mlab.sh
Back to the feed
vulnerability

Siemens IAM Client

Critical
Summary

Siemens has identified a critical unquoted search path vulnerability in its IAM Client SDK, potentially allowing an authenticated local attacker to escalate privileges. Multiple Siemens products, including COMOS, Designcenter NX, Simcenter 3D, Solid Edge, and Teamcenter, are affected by various versions. Siemens recommends updating to the latest versions to mitigate this risk. The vulnerability is classified as CWE-426 and is being reported by Siemens ProductCERT.

Siemens has discovered a critical unquoted search path vulnerability within its IAM Client SDK. This vulnerability could enable an authenticated local attacker to gain elevated privileges on affected systems. The vulnerability stems from an unvalidated search path, allowing attackers to potentially execute arbitrary code.

Several Siemens products are impacted by this vulnerability, including:

  • COMOS V10.4.5 (versions prior to V10.4.5.0.2)
  • COMOS V10.6 (versions prior to V10.6.1)
  • Designcenter NX (versions prior to V2512.7000)
  • Simcenter 3D (versions prior to V2512.7000)
  • Simcenter Femap V2506 (versions prior to V2506.0003)
  • Simcenter Femap V2512 (versions prior to V2512.0002)
  • Simcenter Nastran (versions prior to V2606)
  • Simcenter STAR-CCM+ (versions prior to V2606)
  • Solid Edge SE2025 (versions prior to V225.0.13.3)
  • Solid Edge SE2026 (versions prior to V226.0.04.003)
  • Teamcenter Visualization V2412 (versions prior to V2412.0012)
  • Teamcenter Visualization V2506 (versions prior to V2506.0009)
  • Teamcenter Visualization V2512 (versions prior to V2512.2605)
  • Tecnomatix Plant Simulation V2404 (versions prior to V2404.0022)
  • Tecnomatix Plant Simulation V2504 (versions prior to V2504.0010)
  • Tecnomatix Process Simulate (versions prior to V2606)

The vulnerability is classified as CWE-426: Untrusted Search Path. Siemens ProductCERT reported this vulnerability to CISA. Siemens strongly recommends updating affected products to the latest versions to address this security risk. For specific version updates, refer to the links provided in the advisory. General recommendations include protecting network access to devices and following Siemens' operational guidelines for Industrial Security. CISA recommends minimizing network exposure and isolating control systems from business networks. Organizations should perform impact analysis and risk assessment prior to deploying defensive measures.

Read the full article at CISA Advisories