Junglewise Threat Intelligence

CVE-2025-40936: Siemens Parasolid Translator out of bounds read in IGS parsing

CVE-2025-40936 · Severity: high · CVSS 7.8 · Published 2025-11-17

Technologies: Siemens Simcenter Femap, Siemens Solid Edge. Vendors: Siemens.

Executive brief

Multiple Siemens engineering and simulation software products are affected by a vulnerability in how they process IGS design files. These tools are used by engineers to create 3D models and perform complex system simulations. If an attacker tricks a user into opening a specially crafted malicious file, they could crash the software or potentially take control of the user's computer to steal data or disrupt operations.

Technical details

An out-of-bounds read vulnerability (CWE-125) exists in the PS/IGES Parasolid Translator Component, which is utilized by Siemens Simcenter Femap and Solid Edge. The flaw is triggered during the parsing of specially crafted IGS (Initial Graphics Exchange Specification) files. An attacker can exploit this by providing a malicious file to a user; upon opening, the application may read beyond allocated memory buffers. This can result in a denial-of-service (crash) or arbitrary code execution in the context of the current process. Siemens has released updates for the translator component and the integrated software suites to address this issue.

Affected products

  • Siemens PS/IGES Parasolid Translator Component < V29.0.258
  • Siemens Simcenter Femap < V2512.0003
  • Siemens Solid Edge < V226.00 Update 03

Timeline

  • 2025-11-17: disclosed: Initial disclosure for PS/IGES Parasolid Translator Component
  • 2025-11-17: patched: PS/IGES Parasolid Translator Component V29.0.258 released
  • 2026-02-10: advisory: Advisory updated to include Solid Edge impact
  • 2026-06-09: advisory: Advisory updated to include Simcenter Femap impact

References

Related threats