CVE-2025-40809
7.8Siemens · Solid Edge
Siemens Solid Edge contains an out of bounds write vulnerability in the way it parses PRT files, which could lead to application crashes or remote code execution.
Executive summary
A critical out of bounds write vulnerability in Siemens Solid Edge allows for potential code execution when processing malicious PRT files.
Vulnerability
The application is susceptible to an out of bounds write (CWE-787) triggered during the parsing of specially crafted PRT files. This flaw can be exploited by an attacker to crash the software or execute arbitrary code within the context of the current user process.
Business impact
The ability to achieve remote code execution poses a severe risk to organizational assets, as it allows attackers to compromise the integrity and availability of the host system. Given the CVSS score of 7.8, this vulnerability is classified as High, indicating that successful exploitation could lead to significant unauthorized system access or data loss.
Remediation
Immediate Action: Update Siemens Solid Edge to version V224.0 Update 14 or V225.0 Update 6 respectively, as specified in the official Siemens security advisory.
Proactive Monitoring: Monitor system logs for unexpected application termination or unusual process spawning behavior linked to the Solid Edge executable.
Compensating Controls: Restrict file access to only trusted sources and ensure that users do not open PRT files from untrusted or unknown origins until the software is patched.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Organizations utilizing Siemens Solid Edge must prioritize the application of the provided vendor updates. Because this vulnerability allows for code execution, the risk of full system compromise is substantial, necessitating immediate patching of all affected workstations and engineering environments to prevent exploitation.