CVE-2025-40829
7.8Siemens · Simcenter Femap
Siemens Simcenter Femap contains an uninitialized memory vulnerability in its SLDPRT file parser, which may allow local attackers to execute arbitrary code.
Executive summary
A critical uninitialized memory vulnerability in Siemens Simcenter Femap could allow an attacker to achieve code execution through the processing of malicious SLDPRT files.
Vulnerability
The software contains an uninitialized memory flaw (CWE-908) that is triggered during the parsing of specially crafted SLDPRT files. This vulnerability requires the victim to open a malicious file, but it does not require prior authentication from the attacker.
Business impact
The exploitation of this vulnerability could lead to arbitrary code execution within the context of the user running the application. Given the CVSS score of 7.8, this represents a high-severity risk that could result in full system compromise, data theft, or the installation of persistent malware if an attacker successfully lures a user into opening a manipulated file.
Remediation
Immediate Action: Update Siemens Simcenter Femap to version V2512 or later as specified in the official Siemens security advisory.
Proactive Monitoring: Monitor system logs for unusual application crashes or unexpected child processes spawned by Simcenter Femap.
Compensating Controls: Implement strict controls over the ingestion of external CAD files and ensure that users are trained to avoid opening SLDPRT files from untrusted or unverified sources.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Organizations utilizing Siemens Simcenter Femap should prioritize the transition to version V2512 to eliminate this memory corruption risk. Administrators should ensure that all instances are updated promptly to prevent potential exploitation via malicious file attachments.