CVE-2025-40740

7.8

Siemens · Solid Edge SE2025

Siemens Solid Edge SE2025 contains an out-of-bounds read vulnerability when parsing specially crafted PAR files, which can lead to remote code execution.

Executive summary

An out-of-bounds read vulnerability in Siemens Solid Edge SE2025 allows an attacker to execute arbitrary code by supplying a malicious PAR file.

Vulnerability

This vulnerability is an out-of-bounds read occurring during the parsing of specially crafted PAR files. An attacker can trigger this flaw by enticing a user to open a malicious file, leading to potential code execution within the context of the application process.

Business impact

The ability for an attacker to achieve remote code execution poses a severe risk to organizational security and data integrity. Given the CVSS score of 7.8, this high-severity flaw could lead to full system compromise if the application is run with elevated privileges or used to process sensitive internal designs.

Remediation

Immediate Action: Update Siemens Solid Edge SE2025 to version V225.0 Update 5 or later as specified in the official vendor advisory.

Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous behavior when opening CAD files from untrusted sources.

Compensating Controls: Restrict the opening of PAR files from unknown or untrusted originators to reduce the likelihood of interaction with malicious content.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

The severity of this vulnerability necessitates immediate attention for all deployments of Siemens Solid Edge SE2025. Administrators must prioritize the application of the vendor-provided security update to remediate the underlying parsing flaw and prevent potential code execution attacks.

More Siemens CVEs

Sources