CVE-2025-40936
7.8Siemens · PS/IGES Parasolid Translator Component, Simcenter Femap, Solid Edge
Siemens CAD and translator components contain an out-of-bounds read vulnerability when parsing crafted IGS files, which may lead to application crashes or arbitrary code execution.
Executive summary
A critical out-of-bounds read vulnerability in multiple Siemens applications allows attackers to potentially execute arbitrary code or crash the software via malicious IGS files.
Vulnerability
The vulnerability is an out-of-bounds read occurring during the parsing of specially crafted IGS files. This flaw can be triggered by an unauthenticated attacker providing a malicious file, resulting in system impact within the context of the current process.
Business impact
The potential for arbitrary code execution poses a severe risk to intellectual property and operational integrity. Given the CVSS score of 7.8, this high-severity vulnerability could lead to unauthorized system control or significant data loss within engineering environments. Successful exploitation would disrupt design workflows and potentially compromise sensitive CAD data.
Remediation
Immediate Action: Update the affected Siemens applications to the versions specified in the vendor security advisories to resolve the underlying parsing flaw.
Proactive Monitoring: Implement application-level monitoring to detect unexpected process termination or anomalous memory usage when importing external IGS files.
Compensating Controls: Restrict the import of IGES files from untrusted sources and enforce strict file validation policies within the CAD environment to minimize exposure to malicious payloads.
Exploitation status
Public Exploit Available: No — there is no confirmed public exploit or weaponized code available for this vulnerability.
Analyst recommendation
Security teams must prioritize patching these Siemens components immediately to prevent potential code execution. Ensure that all CAD workstations and server-side translator instances are updated to the latest secure versions provided by the vendor to eliminate the exposure to this out-of-bounds read defect.