# Siemens IAM Client Unquoted Path Flaw

Published: 2026-07-21 · Severity: medium · Sectors: energy, manufacturing
Canonical: https://vorant.io/reports/154d5e44-e4d7-5eae-9625-7ab64025fe42/siemens-iam-client-unquoted-path-flaw

> An unquoted search path bug in Siemens IAM Client SDK lets local authenticated users escalate privileges across multiple Siemens engineering products.

CISA republished a Siemens ProductCERT advisory describing CVE-2025-40945, an untrusted/unquoted search path vulnerability (CWE-426) affecting the IAM Client SDK used across a wide range of Siemens industrial and engineering software, including COMOS, Solid Edge, Teamcenter Visualization, Simcenter products, and Tecnomatix Plant Simulation. The flaw could allow an authenticated local attacker to escalate privileges by exploiting the way the affected software searches for executables in an untrusted path.

Siemens has released patched versions for most affected products and is preparing fixes for the remaining ones, providing update links per product. No public exploitation has been reported; the vulnerability requires local authenticated access rather than remote network access, limiting its immediate risk. Affected sectors per Siemens include chemical, critical manufacturing, and energy, with deployments worldwide from a Germany-headquartered vendor. CISA recommends standard ICS network isolation and defense-in-depth practices alongside applying vendor patches.

## Mentioned in this report

- Vulnerabilities: CVE-2025-40945

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-202-05

---

This is the free public brief from Vorant Threat Intelligence. When citing, attribute "Vorant" and link https://vorant.io/reports/154d5e44-e4d7-5eae-9625-7ab64025fe42/siemens-iam-client-unquoted-path-flaw.
Full IOC sets, deployable detections, the entity graph, TAXII 2.1 feed and real-time alerts: https://vorant.io/signup
