ZDI-CAN-26755: ZDI-25-1042: Siemens Simcenter Femap IGS File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-40936.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-26755?
ZDI-CAN-26755 has a CVSS score indicating a high severity level due to the potential for remote code execution.
How do I fix ZDI-CAN-26755?
To mitigate ZDI-CAN-26755, it is recommended to apply the latest patches or updates from Siemens for Simcenter Femap.
Who is affected by ZDI-CAN-26755?
ZDI-CAN-26755 affects installations of Siemens Simcenter Femap prior to the security update.
Can ZDI-CAN-26755 be exploited without user interaction?
No, ZDI-CAN-26755 requires user interaction, such as visiting a malicious page or opening a malicious file, to exploit.
What type of vulnerability is ZDI-CAN-26755?
ZDI-CAN-26755 is a remote code execution vulnerability that allows attackers to execute arbitrary code on affected systems.