CVE-2026-23716

7.8

Siemens · Simcenter Femap and Simcenter Nastran

Siemens Simcenter Femap and Nastran are vulnerable to an out of bounds read when parsing XDB files, which may allow local code execution.

Executive summary

A critical out of bounds read vulnerability in Siemens Simcenter Femap and Nastran could allow an attacker to achieve remote code execution through the processing of malicious XDB files.

Vulnerability

This vulnerability involves an out of bounds read flaw triggered during the parsing of specially crafted XDB files. The attack requires user interaction, such as opening a malicious file, and can be executed by an unauthenticated local user.

Business impact

Successful exploitation of this vulnerability allows an attacker to execute arbitrary code in the context of the current process, potentially leading to a complete compromise of the affected host. With a CVSS score of 7.8, this flaw represents a significant risk to engineering workstations where sensitive intellectual property or proprietary designs are stored. Organizations face potential data theft, loss of design integrity, and unauthorized access to critical infrastructure simulation environments.

Remediation

Immediate Action: Update both Simcenter Femap and Simcenter Nastran to version V2512 or later immediately to resolve the vulnerable parsing logic.

Proactive Monitoring: Monitor systems for unusual application crashes or unexpected child processes spawned by Simcenter software during the file import or loading process.

Compensating Controls: Implement strict file access policies and ensure that users do not open XDB files from untrusted or unknown sources to prevent the triggering of the vulnerability.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Given the potential for code execution, security teams must prioritize the deployment of the V2512 update across all affected Siemens Simcenter installations. Ensure that users are educated on the risks of opening XDB files from unverified third parties until the software has been successfully patched. Failure to remediate this vulnerability leaves workstations exposed to arbitrary code execution if a user is tricked into loading a malicious design file.

More Siemens CVEs

Sources