ZDI-25-130: Siemens Simcenter Femap NEU File Parsing Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-25175.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-130?
The vulnerability ZDI-25-130 has a critical severity rating as it allows remote code execution.
How do I fix ZDI-25-130?
To mitigate ZDI-25-130, update to the latest version of Siemens Simcenter Femap as released by Siemens.
Who is affected by ZDI-25-130?
Users of Siemens Simcenter Femap are affected by the vulnerability ZDI-25-130.
What types of exploits can be performed using ZDI-25-130?
Exploiting ZDI-25-130 can allow attackers to execute arbitrary code on the affected system.
Is user interaction required to exploit ZDI-25-130?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file.