Siemens Product Security Update Advisory

Siemens Product Security Update Advisory

A security update has been released to address vulnerabilities found in Siemens products. This update applies to multiple products, and users should upgrade to the latest version as instructed.

Resolved Vulnerabilities

  • CVE-2025-40945: A privilege escalation vulnerability caused by an untrusted search path in the Siemens IAM Client.
  • CVE-2026-56451: A authentication bypass vulnerability in Opcenter X.

Affected Products and Versions

  • COMOS V10.4.5: Versions prior to 10.4.5.0.2.
  • COMOS V10.6: Versions prior to 10.6.1.
  • Designcenter NX: versions prior to 2512.7000.
  • Simcenter 3D: versions prior to 2512.7000.
  • Simcenter Femap V2506: versions prior to 2506.0003.
  • Simcenter Femap V2512: Earlier than 2512.0002.
  • Simcenter Nastran: Earlier than 2606.
  • Simcenter STAR-CCM+: Earlier than 2606.
  • Solid Edge SE2025: Earlier than 225.0 Update 13.
  • Solid Edge SE2026: Earlier than 226.0 Update 04.
  • Teamcenter Visualization V2412: Earlier than 2412.0012.
  • Teamcenter Visualization V2506: Earlier than 2506.0009.
  • Teamcenter Visualization V2512: Earlier than 2512.2605.
  • Tecnomatix Plant Simulation V2404: versions earlier than 2404.0022.
  • Tecnomatix Plant Simulation V2504: versions earlier than 2504.0010.
  • Tecnomatix Process Simulate: versions earlier than 2606.
  • Opcenter X: Versions earlier than V2604.

Recommended Actions

Siemens recommends updating to the latest version with Vulnerability Patches, as outlined on the reference sites. After updating, users must ensure they are using versions that meet or exceed the revised baseline versions for each product.

Reference Sites

  • SSA-288252: Advisory regarding the Unquoted Search Path vulnerability in IAM Client.
  • SSA-096828: Advisory regarding the Token Invalidation vulnerability in Opcenter X.