Siemens IAM Client
Multiple Siemens products contain an unquoted search path vulnerability in the IAM Client component. This vulnerability allows an authenticated local attacker with high privileges to perform privilege escalation on the affected workstation. Affected products span the design, simulation, and visualization tool suite including COMOS, Designcenter NX, Simcenter family, Solid Edge, Teamcenter Visualization, and Tecnomatix products. Siemens has released patches for all affected products. The vulnerability requires local access and administrative-level privileges to exploit.
- Local access to the workstation running a vulnerable Siemens product
- High privileges (administrator or equivalent) on the affected machine
- Ability to write files to a directory in the unquoted search path (typically system or application directories)
- The vulnerable process must run automatically or be triggered by an authorized user
Patching may require device reboot — plan for process interruption
/api/v1/advisories/f7b52072-8279-4303-9359-ec334c7df7f2Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.