CVE-2025-40936
published 2025-11-17CVE-2025-40936: A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Simcenter Femap (All versions < V2512.0003), Solid…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.20%
9.8th percentile
A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Simcenter Femap (All versions < V2512.0003), Solid Edge (All versions < V226.00 Update 03). The affected applications contains an out of bounds read vulnerability while parsing specially crafted IGS files. This could allow an attacker to crash the application or execute code in the context of the current process. (ZDI-CAN-26755)
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | ps_iges_parasolid_translator_component | < V29.0.258 | V29.0.258 |
| siemens | simcenter_femap | < V2512.0003 | V2512.0003 |
| siemens | solid_edge | < V226.00 Update 03 | V226.00 Update 03 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv4.07.3HIGHCVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Solid Edge
cisa_ics·2026-02-12·CVSS 7.8
[HIGH] Siemens Solid Edge
ICS Advisory
##
Siemens Solid Edge
Release DateFebruary 12, 2026
Alert CodeICSA-26-043-05
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
View CSAF
## Summary
Solid Edge uses PS/IGES Parasolid Translator Component that contains an out of bounds read that could be triggered when the application reads files in IGS file formats. If a user is tricked to open a malicious file with any of the affected products, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Solid Edge and recommends to update to the latest version.
The following versions of Siemens Solid Edge are affected:
- Solid Edge: All versions prior to V226.00 Update 03
CVSS
Vendor
Equipm
GHSA
GHSA-295f-pwgh-q72q: A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29
ghsa_unreviewed·2025-11-17
CVE-2025-40936 [HIGH] CWE-125 GHSA-295f-pwgh-q72q: A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29
A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258). The affected applications contains an out of bounds read vulnerability while parsing specially crafted IGS files. This could allow an attacker to crash the application or execute code in the context of the current process. (ZDI-CAN-26755)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2025-11-17
Published