CVE-2025-40762
7.8Siemens · Simcenter Femap
Siemens Simcenter Femap contains an out of bounds write vulnerability triggered by parsing malicious STP files, which may lead to arbitrary code execution.
Executive summary
A critical out of bounds write vulnerability in Siemens Simcenter Femap allows local attackers to execute arbitrary code via specially crafted STP files.
Vulnerability
This is an out of bounds write vulnerability (CWE-787) occurring during the parsing of STP files. The vulnerability allows an attacker to execute code in the context of the current process, requiring the user to open a specially crafted file.
Business impact
Successful exploitation allows an attacker to execute arbitrary code, potentially leading to full system compromise or unauthorized access to sensitive engineering data. While the CVSS score of 7.8 reflects a high-severity risk, the requirement for user interaction and local access slightly moderates the immediate threat profile compared to remote network-based exploits.
Remediation
Immediate Action: Update Siemens Simcenter Femap to version V2406.0003 or V2412.0002, or newer, as specified in the Siemens security advisory.
Proactive Monitoring: Monitor systems for unexpected process execution or abnormal application crashes when importing or opening STP files.
Compensating Controls: Advise users to exercise caution when opening STP files from untrusted or unknown sources to prevent the triggering of malicious payloads.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the potential for code execution, organizations utilizing Siemens Simcenter Femap should prioritize patching during the next maintenance cycle. Ensure that all users are aware of the risks associated with opening files from unverified origins until the software has been updated to the corrected versions.