Siemens IAM Client Vulnerability: Privilege Escalation Risk

Multiple Siemens products affected by unquoted search path vulnerability in IAM Client. Update to latest versions to prevent privilege escalation.

miércoles, 22 de julio de 2026 • 3 min read • Q2BSTUDIO Team

Actualiza tu software Siemens para evitar riesgos

Siemens has identified a critical vulnerability in its IAM Client (Identity and Access Management Client) component affecting multiple products in its engineering and simulation ecosystem. This is an unquoted search path flaw that, when exploited locally by an authenticated user, allows privilege escalation within the system. Although the CVSS v3.1 score is 6.7 (MEDIUM), the potential impact on industrial environments is considerable, as these products are deployed in critical sectors such as chemicals, advanced manufacturing, and energy. The vulnerability, registered as CVE-2025-40945, resides in the IAM Client SDK. By failing to properly quote paths in the library search process, an attacker with local access can place a malicious executable in a path that the system will traverse before the legitimate one, thereby executing code with higher privileges. For example, if an application searches for a file in a path like C:\Program Files\MyApp\bin, the system will first look in C:\Program (treating the space as a delimiter) and then in C:\Program Files\MyApp\bin, allowing a malicious executable in C:\Program to be launched with the application's permissions. This is especially dangerous on workstations where engineers and operators have sessions started with high-level credentials.

Affected products include versions of COMOS, Designcenter NX, Simcenter 3D, Simcenter Femap, Simcenter Nastran, Simcenter STAR-CCM+, Solid Edge, Teamcenter Visualization, Tecnomatix Plant Simulation, and Tecnomatix Process Simulate, among others. Each product has a specific version from which the flaw is fixed; for example, COMOS V10.6.1, Solid Edge SE2025 Update 13, Teamcenter Visualization V2412.0012, etc. Siemens has released updates for most of them and recommends applying them immediately. For products without a patch yet, compensatory measures are suggested, such as limiting local access, disabling unnecessary accounts, and monitoring suspicious activity. CISA has republished the advisory and recommends minimizing network exposure of control systems, using firewalls, and segmenting OT networks from corporate ones.

Beyond the technical fix, this vulnerability underscores the importance of cybersecurity in industrial software, especially when shared components like IAM Client are used. Companies that develop custom software must pay special attention to secure coding practices, such as proper handling of search paths and input validation. At Q2BSTUDIO, as a software development and technology company, we understand that security is not an add-on but a fundamental pillar in any project, whether it is a custom application, an artificial intelligence system, or a cloud platform. For example, when designing a cloud solution on AWS or Azure, it is crucial to correctly configure permissions and execution paths to avoid similar attack vectors. Likewise, in the field of artificial intelligence and AI agents, the integrity of the underlying software determines the reliability of the results. Cybersecurity must be integrated from the design phase, with penetration testing and periodic audits.

The incident also highlights the need to protect Business Intelligence systems. A privilege escalation could provide access to Power BI dashboards or databases containing sensitive company information, compromising strategic decision-making. Therefore, we recommend reviewing the security of your BI environments and considering the implementation of AI agents that monitor anomalous behavior in real time. At Q2BSTUDIO we offer cybersecurity and pentesting services to assess and strengthen your infrastructure's security posture, as well as custom software development with a comprehensive focus on quality and security. Additionally, we integrate cloud technologies such as AWS and Azure, artificial intelligence, and process automation to create robust solutions prepared to face threats like the one described here.

The lessons from this vulnerability are clear: even the largest vendors can have subtle security flaws, and organizations must maintain a rigorous update program, segment their networks, and collaborate with cybersecurity experts to minimize risks. Integrating secure practices into the software development lifecycle is the best defense against threats like privilege escalation. In a world where digitalization is advancing rapidly, trust in systems depends on their ability to withstand local and remote attacks. At Q2BSTUDIO, we invite companies to assess their security posture and consider our customized software, BI, AI, and cloud solutions to build a safer and more efficient future.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.