CVE-2026-23719
7.8Siemens · Simcenter Femap and Simcenter Nastran
A heap-based buffer overflow in Siemens Simcenter Femap and Nastran allows unauthenticated remote attackers to execute arbitrary code via crafted NDB files.
Executive summary
A critical heap-based buffer overflow vulnerability in Siemens Simcenter software could allow an unauthenticated attacker to achieve remote code execution.
Vulnerability
The application is susceptible to a heap-based buffer overflow (CWE-122) when parsing specially crafted NDB files. This flaw allows an unauthenticated attacker to execute code within the context of the current process.
Business impact
The ability for an unauthenticated attacker to execute arbitrary code poses a significant risk to organizational integrity and data confidentiality. Given the CVSS score of 7.8, this vulnerability is classified as High, indicating that successful exploitation could lead to full system compromise, loss of intellectual property, and operational downtime for engineering environments.
Remediation
Immediate Action: Update all installations of Simcenter Femap and Simcenter Nastran to version V2512 or later as specified in the Siemens security advisory.
Proactive Monitoring: Monitor system logs for abnormal application termination or process crashes that might indicate an exploitation attempt during file parsing.
Compensating Controls: Restrict access to NDB files from untrusted sources and ensure that engineering software runs with the minimum necessary user privileges to limit the impact of a potential code execution event.
Exploitation status
Public Exploit Available: No (exploit_available: false)
Analyst recommendation
This vulnerability presents a clear risk to users of Siemens engineering software. Administrators must prioritize the deployment of the V2512 update across all affected workstations and servers to eliminate the buffer overflow vector. Do not delay implementation, as the potential for remote code execution constitutes a severe security concern.