CVE-2025-40809

7.8

Siemens · Solid Edge

Siemens Solid Edge contains an out of bounds write vulnerability in the way it parses PRT files, which could lead to application crashes or remote code execution.

Executive summary

A critical out of bounds write vulnerability in Siemens Solid Edge allows for potential code execution when processing malicious PRT files.

Vulnerability

The application is susceptible to an out of bounds write (CWE-787) triggered during the parsing of specially crafted PRT files. This flaw can be exploited by an attacker to crash the software or execute arbitrary code within the context of the current user process.

Business impact

The ability to achieve remote code execution poses a severe risk to organizational assets, as it allows attackers to compromise the integrity and availability of the host system. Given the CVSS score of 7.8, this vulnerability is classified as High, indicating that successful exploitation could lead to significant unauthorized system access or data loss.

Remediation

Immediate Action: Update Siemens Solid Edge to version V224.0 Update 14 or V225.0 Update 6 respectively, as specified in the official Siemens security advisory.

Proactive Monitoring: Monitor system logs for unexpected application termination or unusual process spawning behavior linked to the Solid Edge executable.

Compensating Controls: Restrict file access to only trusted sources and ensure that users do not open PRT files from untrusted or unknown origins until the software is patched.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations utilizing Siemens Solid Edge must prioritize the application of the provided vendor updates. Because this vulnerability allows for code execution, the risk of full system compromise is substantial, necessitating immediate patching of all affected workstations and engineering environments to prevent exploitation.

More Siemens CVEs

Sources