CVE-2025-40740
7.8Siemens · Solid Edge SE2025
Siemens Solid Edge SE2025 contains an out-of-bounds read vulnerability when parsing specially crafted PAR files, which can lead to remote code execution.
Executive summary
An out-of-bounds read vulnerability in Siemens Solid Edge SE2025 allows an attacker to execute arbitrary code by supplying a malicious PAR file.
Vulnerability
This vulnerability is an out-of-bounds read occurring during the parsing of specially crafted PAR files. An attacker can trigger this flaw by enticing a user to open a malicious file, leading to potential code execution within the context of the application process.
Business impact
The ability for an attacker to achieve remote code execution poses a severe risk to organizational security and data integrity. Given the CVSS score of 7.8, this high-severity flaw could lead to full system compromise if the application is run with elevated privileges or used to process sensitive internal designs.
Remediation
Immediate Action: Update Siemens Solid Edge SE2025 to version V225.0 Update 5 or later as specified in the official vendor advisory.
Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous behavior when opening CAD files from untrusted sources.
Compensating Controls: Restrict the opening of PAR files from unknown or untrusted originators to reduce the likelihood of interaction with malicious content.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit in the available data.
Analyst recommendation
The severity of this vulnerability necessitates immediate attention for all deployments of Siemens Solid Edge SE2025. Administrators must prioritize the application of the vendor-provided security update to remediate the underlying parsing flaw and prevent potential code execution attacks.