CVE-2025-40764

7.8

Siemens · Simcenter Femap

Siemens Simcenter Femap is vulnerable to an out of bounds read when parsing crafted BMP files, potentially allowing an attacker to execute code in the context of the current process.

Executive summary

An out of bounds read vulnerability in Siemens Simcenter Femap allows attackers to potentially execute arbitrary code through specially crafted BMP files.

Vulnerability

This is an out of bounds read flaw (CWE-125) triggered during the parsing of malformed BMP image files. The vulnerability requires user interaction to open the malicious file, but does not require authentication from the attacker.

Business impact

The ability to execute code in the context of the current process poses a significant risk to organizational integrity and data confidentiality. Given the CVSS score of 7.8, this vulnerability is considered High severity, as it could lead to full system compromise if the application is running with elevated privileges. Successful exploitation could result in unauthorized data access or the installation of persistent malicious software within the engineering environment.

Remediation

Immediate Action: Update to Simcenter Femap version V2406.0003 or V2412.0002 as recommended by the Siemens security advisory.

Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous process behavior following the opening of image files.

Compensating Controls: Implement strict file validation policies and ensure that users do not open BMP files from untrusted or unverified sources.

Exploitation status

Public Exploit Available: No — exploit_available (false).

Analyst recommendation

Organizations utilizing affected versions of Simcenter Femap should prioritize the installation of the provided vendor patches to eliminate the risk of code execution. Users should exercise caution regarding the source of files processed within the application until updates are fully applied across the environment.

More Siemens CVEs

Sources