CVE-2026-23720

7.8

Siemens · Simcenter Femap and Simcenter Nastran

Siemens Simcenter Femap and Simcenter Nastran contain an out of bounds read vulnerability in NDB file parsing that may allow arbitrary code execution.

Executive summary

An out of bounds read vulnerability in Siemens Simcenter Femap and Simcenter Nastran allows attackers to execute code in the context of the current process via malicious NDB files.

Vulnerability

This vulnerability is an out of bounds read flaw occurring during the parsing of specially crafted NDB files. The vulnerability can be triggered by an unauthenticated attacker, provided they can convince a user to open a malicious file within the affected software.

Business impact

Successful exploitation of this flaw allows an attacker to execute arbitrary code within the context of the user running the application. Given the nature of these engineering tools, this could lead to full system compromise, the theft of sensitive proprietary design data, or the disruption of critical engineering workflows. With a CVSS score of 7.8, this represents a high severity risk that necessitates prompt attention to prevent potential data breaches or operational downtime.

Remediation

Immediate Action: Update both Simcenter Femap and Simcenter Nastran to version V2512 or later as specified in the Siemens security advisory.

Proactive Monitoring: Review system access logs for unusual application behavior or crashes occurring when importing or opening NDB files.

Compensating Controls: Implement strict file handling policies that restrict the opening of NDB files from untrusted or external sources until the software has been patched.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The vulnerability poses a high risk to engineering environments due to the potential for remote code execution. Security teams should prioritize patching all instances of Siemens Simcenter Femap and Simcenter Nastran to version V2512. Users should be cautioned against opening NDB files from untrusted sources until the remediation is fully applied across the organization.

More Siemens CVEs

Sources