Executive brief
Siemens Solid Edge, a professional 3D computer-aided design (CAD) software, is vulnerable to a security flaw when processing specific part (PAR) files. An attacker could trick a user into opening a malicious file, which could lead to the software crashing or allowing the attacker to take control of the user's computer. This could result in the theft of intellectual property or a disruption of engineering operations.
Technical details
A stack-based buffer overflow (CWE-121) exists in Siemens Solid Edge SE2026 within the PAR file parsing component. The vulnerability is triggered when the application processes a specially crafted PAR file. An attacker can exploit this by convincing a user to open a malicious file, leading to memory corruption. Successful exploitation could allow for arbitrary code execution in the context of the current process. Siemens has addressed this in Solid Edge SE2026 V226.0 Update 5.
Affected products
- Siemens Solid Edge SE2026 All versions < V226.0 Update 5
Timeline
- 2026-05-12: disclosed
- 2026-05-12: advisory
- 2026-05-12: patched