CVE-2025-40812

7.8

Siemens · Solid Edge

Siemens Solid Edge SE2024 and SE2025 contain an out-of-bounds read vulnerability that may allow a local attacker to crash the application or execute code via specially crafted PRT files.

Executive summary

A critical out-of-bounds read vulnerability in Siemens Solid Edge allows for potential application crashes or remote code execution when parsing malicious files.

Vulnerability

This vulnerability is an out-of-bounds read (CWE-125) triggered during the parsing of specially crafted PRT files. The attack requires user interaction to open the malicious file, but it does not require prior authentication to trigger.

Business impact

The potential for arbitrary code execution poses a significant risk to organizational assets, as an attacker could gain the same privileges as the user running the software. Given the CVSS score of 7.8, this vulnerability is classified as High severity, indicating that successful exploitation could lead to full loss of confidentiality, integrity, and availability within the context of the affected process. This could result in intellectual property theft or the disruption of engineering workflows.

Remediation

Immediate Action: Update Siemens Solid Edge to version V224.0 Update 14 or V225.0 Update 6, depending on the installed release, as specified in the vendor security advisory.

Proactive Monitoring: Monitor system logs for unexpected application crashes or abnormal memory usage patterns associated with Solid Edge while processing PRT files.

Compensating Controls: Implement strict file access controls and utilize endpoint protection solutions to scan incoming PRT files from untrusted sources for malicious patterns before they are opened by users.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Organizations utilizing Siemens Solid Edge must prioritize these updates to eliminate the risk of arbitrary code execution. Given that the vulnerability is triggered by parsing files, administrators should also emphasize secure file-handling practices to users until the patching process is complete across the enterprise environment.

More Siemens CVEs

Sources