ZDI-25-1042: Siemens Simcenter Femap IGS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-40936.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-1042?
The severity of ZDI-25-1042 is determined by the CVSS score provided in the advisory, indicating a significant risk due to the potential for arbitrary code execution.
How do I fix ZDI-25-1042?
To fix ZDI-25-1042, ensure that you apply the latest security updates provided by Siemens for Simcenter Femap.
What type of attack can exploit ZDI-25-1042?
ZDI-25-1042 can be exploited through a remote attack that requires user interaction, such as visiting a malicious page or opening a harmful file.
Who is affected by ZDI-25-1042?
Users of Siemens Simcenter Femap are affected by ZDI-25-1042, particularly those who have not updated their software to the latest version.
Is user interaction required for ZDI-25-1042 exploitation?
Yes, user interaction is required for the exploitation of ZDI-25-1042, as the target must open a malicious document or visit a compromised webpage.