CVE-2025-40811
7.8Siemens · Solid Edge
Siemens Solid Edge contains an out-of-bounds read vulnerability in the PRT file parser that may allow an attacker to crash the application or execute arbitrary code.
Executive summary
A critical out-of-bounds read vulnerability in Siemens Solid Edge allows for potential application crashes or remote code execution via malicious PRT files.
Vulnerability
The software suffers from an out-of-bounds read vulnerability (CWE-125) triggered during the parsing of specially crafted PRT files. This flaw can be exploited by an attacker to execute code within the context of the current process, requiring user interaction to open the malicious file.
Business impact
The ability to execute code in the context of the current process poses a significant risk to data integrity and system security. Successful exploitation could lead to unauthorized access to sensitive engineering data or complete system compromise. With a CVSS score of 7.8, this vulnerability is classified as High, reflecting the potential for significant impact on organizational operations.
Remediation
Immediate Action: Update Siemens Solid Edge to version V224.0 Update 14 or V225.0 Update 6, as specified in the official Siemens security advisory.
Proactive Monitoring: Monitor workstation and server logs for abnormal application termination events or unexpected process behavior associated with the Solid Edge executable.
Compensating Controls: Restrict the ability of users to open PRT files from untrusted or external sources and ensure that endpoint protection solutions are configured to scan files upon access.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
Given the potential for code execution, organizations using Siemens Solid Edge should prioritize the application of the vendor-provided patches. Administrators must ensure that all instances of the affected software are updated to the specified versions to mitigate the risk of exploitation. Continued vigilance regarding the source of imported PRT files is recommended until all systems are fully patched.