Siemens IAM Client

MonitorCVSS 6.7ICS-CERT ICSA-26-202-05Jul 14, 2026
Siemens
Attack path
Attack VectorLocal
Auth RequiredHigh
ComplexityLow
User InteractionNone needed
Summary

Multiple Siemens products contain an unquoted search path vulnerability in the IAM Client component. This vulnerability allows an authenticated local attacker with high privileges to perform privilege escalation on the affected workstation. Affected products span the design, simulation, and visualization tool suite including COMOS, Designcenter NX, Simcenter family, Solid Edge, Teamcenter Visualization, and Tecnomatix products. Siemens has released patches for all affected products. The vulnerability requires local access and administrative-level privileges to exploit.

What this means
What could happen
An authenticated local attacker with high privileges could exploit unquoted search path issues in the IAM Client to escalate their privileges and gain full control of the workstation, potentially compromising engineering environments or control system design tools.
Who's at risk
Engineering teams and plant engineers using Siemens design and simulation tools should be concerned. Affected products include COMOS, Designcenter NX, Simcenter suite (3D, Femap, Nastran, STAR-CCM+), Solid Edge CAD, Teamcenter Visualization, and Tecnomatix Plant Simulation and Process Simulate. These are typically used on engineering workstations in manufacturing, automotive, and heavy industry facilities. The vulnerability requires local access and elevated privileges, so it is primarily a risk for insider threats or compromised insider accounts.
How it could be exploited
An attacker with local access and administrative or elevated privileges on a machine running a vulnerable Siemens product could place a malicious DLL or executable in the unquoted search path. When the IAM Client runs, it may load the attacker's code instead of the legitimate library, executing commands with the privileges of the process.
Prerequisites
  • Local access to the workstation running a vulnerable Siemens product
  • High privileges (administrator or equivalent) on the affected machine
  • Ability to write files to a directory in the unquoted search path (typically system or application directories)
  • The vulnerable process must run automatically or be triggered by an authorized user
Low attack complexityHigh privilege requirement to exploitLocal access only (not remotely exploitable)Affects design and engineering tools (not directly OT control systems)
Exploitability
Unlikely to be exploited — EPSS score 0.2%
Affected products (16)
16 with fix
ProductAffected VersionsFix Status
COMOS V10.4.5 < V10.4.5.0.2< 10.4.5.0.210.4.5.0.2
COMOS V10.6 < V10.6.1< 10.6.110.6.1
Designcenter NX < V2512.7000< 2512.70002512.7000
Simcenter 3D < V2512.7000< 2512.70002512.7000
Simcenter Femap V2506 < V2506.0003< 2506.00032506.0003
Remediation & Mitigation
0/11
Schedule — requires maintenance window
0/10

Patching may require device reboot — plan for process interruption

HOTFIXUpdate COMOS to version 10.6.1 or later
HOTFIXUpdate Designcenter NX to version 2512.7000 or later
HOTFIXUpdate Simcenter 3D to version 2512.7000 or later
HOTFIXUpdate Simcenter Femap to version 2506.0003 or later (V2506 branch) or 2512.0002 or later (V2512 branch)
HOTFIXUpdate Simcenter Nastran to version 2606 or later
HOTFIXUpdate Simcenter STAR-CCM+ to version 2606 or later
HOTFIXUpdate Solid Edge to version 225.0 Update 13 or later (SE2025) or 226.0 Update 04 or later (SE2026)
HOTFIXUpdate Teamcenter Visualization to version 2412.0012 or later, 2506.0009 or later, or 2512.2605 or later depending on your deployed version
HOTFIXUpdate Tecnomatix Plant Simulation to version 2404.0022 or later or 2504.0010 or later depending on your deployed version
HOTFIXUpdate Tecnomatix Process Simulate to version 2606 or later
Long-term hardening
0/1
HARDENINGRestrict local administrator privileges on workstations to only users who require them for their role
API: /api/v1/advisories/f7b52072-8279-4303-9359-ec334c7df7f2

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Siemens IAM Client | CVSS 6.7 - OTPulse