CVE-2025-40936: High severity Siemens PS/IGES Parasolid Translator Component vulnerability
A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Simcenter Femap (All versions < V2512.0003), Solid Edge (All versions < V226.00 Update 03). The affected applications contains an out of bounds read vulnerability while parsing specially crafted IGS files. This could allow an attacker to crash the application or execute code in the context of the current process. (ZDI-CAN-26755)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-40936?
CVE-2025-40936 has a critical severity rating due to its potential for application crashes and code execution.
How do I fix CVE-2025-40936?
To mitigate CVE-2025-40936, upgrade to Siemens PS/IGES Parasolid Translator Component version 29.0.258 or later.
Which versions are affected by CVE-2025-40936?
CVE-2025-40936 affects all versions of Siemens PS/IGES Parasolid Translator Component prior to 29.0.258.
What type of vulnerability is CVE-2025-40936?
CVE-2025-40936 is categorized as an out of bounds read vulnerability.
Can CVE-2025-40936 allow remote code execution?
Yes, CVE-2025-40936 could potentially allow an attacker to execute code on the affected application.