Siemens Product Security Update Advisory
A security update has been released to address vulnerabilities found in Siemens products. This update applies to multiple products, and users should upgrade to the latest version as instructed.
Resolved Vulnerabilities
CVE-2025-40945: A privilege escalation vulnerability caused by an untrusted search path in the Siemens IAM Client.CVE-2026-56451: A authentication bypass vulnerability in Opcenter X.
Affected Products and Versions
- COMOS V10.4.5: Versions prior to
10.4.5.0.2. - COMOS V10.6: Versions prior to
10.6.1. - Designcenter NX: versions prior to
2512.7000. - Simcenter 3D: versions prior to
2512.7000. - Simcenter Femap V2506: versions prior to
2506.0003. - Simcenter Femap V2512: Earlier than
2512.0002. - Simcenter Nastran: Earlier than
2606. - Simcenter STAR-CCM+: Earlier than
2606. - Solid Edge SE2025: Earlier than
225.0 Update 13. - Solid Edge SE2026: Earlier than
226.0 Update 04. - Teamcenter Visualization V2412: Earlier than
2412.0012. - Teamcenter Visualization V2506: Earlier than
2506.0009. - Teamcenter Visualization V2512: Earlier than
2512.2605. - Tecnomatix Plant Simulation V2404: versions earlier than
2404.0022. - Tecnomatix Plant Simulation V2504: versions earlier than
2504.0010. - Tecnomatix Process Simulate: versions earlier than
2606. - Opcenter X: Versions earlier than
V2604.
Recommended Actions
Siemens recommends updating to the latest version with Vulnerability Patches, as outlined on the reference sites. After updating, users must ensure they are using versions that meet or exceed the revised baseline versions for each product.
Reference Sites
SSA-288252: Advisory regarding the Unquoted Search Path vulnerability in IAM Client.SSA-096828: Advisory regarding the Token Invalidation vulnerability in Opcenter X.