Executive brief
Simcenter Femap is a finite element analysis tool used to create and inspect complex engineering simulations. An out-of-bounds memory read vulnerability in BMP file parsing could allow an attacker to execute arbitrary code if a user opens a malicious BMP file, compromising the integrity of engineering simulations and potentially enabling access to sensitive design data.
Technical details
CVE-2026-59700 is an out-of-bounds read vulnerability (CWE-125) in Simcenter Femap's BMP file parsing logic. The vulnerability is triggered when a specially crafted BMP file is processed by the application, allowing an attacker to read memory beyond allocated bounds. Attack precondition: user interaction is required—the user must be tricked into opening a malicious BMP file. The attack vector is local. Successful exploitation can lead to arbitrary code execution in the context of the Femap process. Siemens has released patches in version V2606.0001 and later.
Affected products
- Siemens Simcenter Femap All versions < V2606.0001
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Update to V2606.0001 or later available