CVE-2025-40741

7.8

Siemens · Solid Edge SE2025

A stack-based buffer overflow in Siemens Solid Edge SE2025 allows local attackers to execute arbitrary code by supplying a specially crafted CFG file.

Executive summary

A critical stack-based buffer overflow vulnerability in Siemens Solid Edge SE2025 poses a significant risk of arbitrary code execution for local users.

Vulnerability

The application is susceptible to a stack-based buffer overflow (CWE-121) when parsing malformed CFG configuration files. An attacker can exploit this flaw to execute code within the context of the current process, requiring the victim to open a malicious file.

Business impact

Successful exploitation of this vulnerability allows an attacker to achieve code execution on the local workstation, potentially leading to unauthorized data access or complete system compromise. Given the CVSS score of 7.8, this flaw represents a high-severity risk that could disrupt engineering operations or facilitate lateral movement within a corporate network.

Remediation

Immediate Action: Update Siemens Solid Edge SE2025 to version V225.0 Update 5 or later to resolve the underlying buffer overflow.

Proactive Monitoring: Monitor workstation logs for unexpected process crashes or abnormal application behavior related to Solid Edge.

Compensating Controls: Restrict the ability of users to open untrusted CFG files from external sources and ensure that users operate with the principle of least privilege to limit the impact of potential code execution.

Exploitation status

Public Exploit Available: No

Analyst recommendation

This vulnerability presents a clear risk to local system integrity and should be prioritized for remediation. Organizations utilizing Solid Edge SE2025 must apply the vendor-provided update to V225.0 Update 5 immediately to eliminate the possibility of code execution through malicious file parsing.

More Siemens CVEs

Sources