CVE-2025-40762

Severity
7.3HIGH
EPSS
0.0%
top 95.40%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedAug 12

Description

A vulnerability has been identified in Simcenter Femap V2406 (All versions < V2406.0003), Simcenter Femap V2412 (All versions < V2412.0002). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted STP file. This could allow an attacker to execute code in the context of the current process.(ZDI-CAN-26692)

CVSS vector

CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Packages3 packages

CVEListV5siemens/simcenter_femap_v2406< V2406.0003
CVEListV5siemens/simcenter_femap_v2412< V2412.0002
NVDsiemens/simcenter_femap2406.00002406.0003+1

🔴Vulnerability Details

2
CVEList
CVE-2025-40762: A vulnerability has been identified in Simcenter Femap V2406 (All versions < V24062025-08-12
GHSA
GHSA-fg9q-q57h-p86x: A vulnerability has been identified in Simcenter Femap V2406 (All versions < V24062025-08-12