Executive brief
Siemens Simcenter Femap, an engineering tool used for creating and inspecting complex simulation models, is vulnerable to a memory corruption flaw. An attacker could exploit this by tricking a user into opening a specially crafted IPT file, potentially leading to unauthorized code execution on the user's system. This could result in a full system compromise, data theft, or disruption of engineering operations.
Technical details
A heap-based buffer overflow (CWE-122) exists in the Datakit library used by Siemens Simcenter Femap. The vulnerability is triggered during the parsing of specially crafted IPT (Autodesk Inventor) files. An attacker can exploit this by providing a malicious file to a user; when the application attempts to process the file, memory corruption occurs. This can be leveraged to execute arbitrary code in the context of the current process. The attack requires user interaction (opening the file) and local access to the file system. Siemens has addressed this in version V2512.0003.
Affected products
- Siemens Simcenter Femap All versions < V2512.0003
Timeline
- 2026-05-12: advisory: Initial Siemens SSA-870926 advisory published
- 2026-05-12: patched: Siemens released version V2512.0003 to address the flaw
- 2026-05-14: advisory: CISA ICSA-26-134-05 published