---
id: CVE-2025-40945
title: >-
  A vulnerability has been identified in COMOS V10.4.5 (All versions <
  V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All
  versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter
  Femap V2506 (All ve…
summary: >-
  A vulnerability has been identified in COMOS V10.4.5 (All versions <
  V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All
  versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter
  Femap V2506 (All ve…
severity: medium
cvss: 6.7
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-426
published: '2026-07-14'
updated: '2026-09-29'
sourceUpdated: '2026-09-29T15:10:00.193'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-40945'
references:
  - url: 'https://cert-portal.siemens.com/productcert/html/ssa-288252.html'
    label: productcert@siemens.com
tags:
  - nvd
epss: 0.00164
epssPercentile: 0.05004
ingestedAt: '2026-09-29T16:39:33.226Z'
---

## Overview

A vulnerability has been identified in COMOS V10.4.5 (All versions < V10.4.5.0.2), COMOS V10.6 (All versions < V10.6.1), Designcenter NX (All versions < V2512.7000), Simcenter 3D (All versions < V2512.7000), Simcenter Femap V2506 (All versions < V2506.0003), Simcenter Femap V2512 (All versions < V2512.0002), Simcenter Nastran (All versions < V2606), Simcenter STAR-CCM+ (All versions < V2606), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0 Update 04), Teamcenter Visualization V2412 (All versions < V2412.0012), Teamcenter Visualization V2506 (All versions < V2506.0009), Teamcenter Visualization V2512 (All versions < V2512.2605), Tecnomatix Plant Simulation V2404 (All versions < V2404.0022), Tecnomatix Plant Simulation V2504 (All versions < V2504.0010), Tecnomatix Process Simulate (All versions < V2606). Untrusted search path in IAM Client SDK may allow an authenticated user to potentially enable escalation of privilege via local access.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
