CVE-2026-23717
7.8Siemens · Simcenter Femap and Simcenter Nastran
Siemens Simcenter Femap and Nastran contain an out-of-bounds read vulnerability in XDB file parsing, which may allow an attacker to execute code in the context of the current process.
Executive summary
An out-of-bounds read vulnerability in Siemens Simcenter Femap and Simcenter Nastran allows for potential arbitrary code execution via malicious XDB files.
Vulnerability
The vulnerability is an out-of-bounds read (CWE-125) occurring during the parsing of specially crafted XDB files. This flaw allows an unauthenticated attacker to trigger a memory corruption condition that may result in code execution within the context of the application process.
Business impact
The potential for arbitrary code execution poses a severe risk to intellectual property and engineering data confidentiality. Given the CVSS score of 7.8, this vulnerability is classified as High severity, as successful exploitation could lead to full system compromise if the application is running with elevated privileges.
Remediation
Immediate Action: Update both Simcenter Femap and Simcenter Nastran to version V2512 or later immediately as specified by the Siemens security advisory.
Proactive Monitoring: Monitor system logs for unexpected application crashes or anomalous behavior when importing or processing engineering model files.
Compensating Controls: Restrict access to XDB files from untrusted sources and ensure that engineering software is executed within the least privileged user context possible.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability represents a significant risk to the integrity of engineering workflows. Organizations using Simcenter Femap or Simcenter Nastran must prioritize the transition to version V2512 to eliminate the underlying memory corruption flaw. Failure to patch may expose sensitive design environments to remote code execution risks.