CVE-2025-25175

CWE-119Buffer Overflow3 documents3 sources
Severity
7.3HIGH
EPSS
0.0%
top 91.80%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMar 13

Description

A vulnerability has been identified in Simcenter Femap V2401 (All versions < V2401.0003), Simcenter Femap V2406 (All versions < V2406.0002). The affected application contains a memory corruption vulnerability while parsing specially crafted .NEU files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-25443)

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages3 packages

CVEListV5siemens/simcenter_femap_v2401< V2401.0003
CVEListV5siemens/simcenter_femap_v2406< V2406.0002
NVDsiemens/simcenter_femap2401.02401.0003+1

🔴Vulnerability Details

2
CVEList
CVE-2025-25175: A vulnerability has been identified in Simcenter Femap V2401 (All versions < V24012025-03-13
GHSA
GHSA-9j8w-rhj2-qxqp: A vulnerability has been identified in Simcenter Femap V2401 (All versions < V24012025-03-13
CVE-2025-25175 (HIGH CVSS 7.3) | A vulnerability has been identified | cvebase.io