CVE-2026-23718

7.8

Siemens · Simcenter Femap and Simcenter Nastran

Siemens Simcenter Femap and Nastran are vulnerable to an out of bounds read when parsing NDB files, potentially allowing an attacker to execute code in the context of the current process.

Executive summary

A critical out of bounds read vulnerability in Siemens Simcenter Femap and Nastran poses a risk of arbitrary code execution to systems processing malicious NDB files.

Vulnerability

The vulnerability is an out of bounds read (CWE-125) triggered during the parsing of specially crafted NDB files. Based on the CVSS vector, this flaw requires local access and user interaction to trigger, yet allows for high impact to confidentiality, integrity, and availability.

Business impact

The ability for an unauthenticated attacker to execute code in the context of the current process presents a significant threat to engineering workstations and simulation environments. While the CVSS score of 7.8 classifies this as a High severity issue, the potential for arbitrary code execution could lead to the theft of sensitive intellectual property or the disruption of critical product design workflows.

Remediation

Immediate Action: Upgrade Siemens Simcenter Femap and Simcenter Nastran to version V2512 or later as specified in the official Siemens security advisory.

Proactive Monitoring: Monitor engineering workstations for unexpected process crashes or abnormal file access patterns when loading NDB files from untrusted sources.

Compensating Controls: Restrict the handling of NDB files to known, trusted origins and utilize file integrity scanning to inspect project data before opening it in the affected software.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Given the potential for remote code execution, security teams must prioritize the deployment of the V2512 update across all affected Siemens installations. Administrators should enforce strict data handling policies regarding external NDB files until all systems are patched to eliminate this vulnerability.

More Siemens CVEs

Sources