First published: Thu Mar 13 2025(Updated: )
A vulnerability has been identified in Simcenter Femap V2401 (All versions < V2401.0003), Simcenter Femap V2406 (All versions < V2406.0002). The affected application contains a memory corruption vulnerability while parsing specially crafted .NEU files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-25443)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simcenter Femap | <V2401.0003 | |
Siemens Simcenter Femap | <V2406.0002 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-25175 is considered a critical memory corruption vulnerability that can lead to code execution.
To mitigate CVE-2025-25175, upgrade Simcenter Femap to version V2401.0003 or V2406.0002 or later.
CVE-2025-25175 affects Simcenter Femap V2401 versions prior to V2401.0003 and V2406 versions prior to V2406.0002.
CVE-2025-25175 involves specially crafted .NEU files that can trigger the memory corruption vulnerability.
Yes, if exploited, CVE-2025-25175 could allow an attacker to execute code, potentially leading to unauthorized access.