Executive brief
Simcenter Femap is an advanced finite element modeling application used by engineers to create and analyze complex product designs. A vulnerability in the application's BMP file parser could allow an attacker to craft a malicious file that, when opened by a user, crashes the application or executes arbitrary code with the user's privileges.
Technical details
CVE-2026-59701 is an out-of-bounds read vulnerability (CWE-125) in Simcenter Femap's BMP file parsing logic. The vulnerability is triggered when the application processes specially crafted BMP files, allowing an attacker to read memory beyond allocated boundaries. Attack vector is local with user interaction required—a victim must be tricked into opening a malicious BMP file. Successful exploitation can lead to arbitrary code execution in the context of the Femap process. The patch is available: update to version V2606.0001 or later.
Affected products
- Siemens Simcenter Femap All versions < V2606.0001
Timeline
- 2026-08-11: disclosed
- 2026-08-11: patched: Fix available in V2606.0001 or later