Description
Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process.
Published: 2026-05-12
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files, which could allow an attacker to execute code in the context of the current process. This is a heap-based buffer overflow (CWE-122) that can overwrite arbitrary memory, potentially compromising the confidentiality and integrity of the affected system by giving attackers code execution with the application user’s privileges.

Affected Systems

Any installation of Siemens Simcenter Femap that processes IPT files and is earlier than the V2512.0003 release is vulnerable. The CNA notes that the affected applications include all versions that do not incorporate the recommended patch, though specific version ranges are not listed. Users should verify whether their deployment is on a pre‑2512.0003 build and consider applying the fix accordingly.

Risk and Exploitability

The CVSS score of 7.3 indicates high severity, and the EPSS score is below 1%, indicating a very low exploitation probability. The vulnerability is not listed in CISA’s KEV catalog. The likely attack vector is inferred from the description: an attacker would need to supply a maliciously crafted IPT file to the application, either locally or through collaborative features that import IPT files. Because the flaw results in code execution within the current process, successful exploitation would grant attacker-level access to the system where Femap is running. The exploitability hinges on the attacker’s ability to deliver the malicious file to the application’s input stream.

Generated by OpenCVE AI on June 4, 2026 at 23:25 UTC.

Remediation

Vendor Solution

Update to V2512.0003 or later version https://support.sw.siemens.com/product/275652363/


OpenCVE Recommended Actions

  • Update Siemens Simcenter Femap to version V2512.0003 or later.
  • Validate any IPT files before opening them, ensuring they come from trusted sources and are scanned for malicious content.
  • Limit user permissions for launching or operating Simcenter Femap to only those who need to work with IPT files, reducing the attack surface.

Generated by OpenCVE AI on June 4, 2026 at 23:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 04 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description The affected applications contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-27349, ZDI-CAN-27389) Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process.
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Tue, 12 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 May 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens simcenter Femap
Vendors & Products Siemens
Siemens simcenter Femap

Tue, 12 May 2026 13:30:00 +0000

Type Values Removed Values Added
Description The affected applications contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-27349, ZDI-CAN-27389)
Title Heap-based buffer overflow in Siemens Simcenter Femap
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Simcenter Femap
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-06-04T20:22:03.369Z

Reserved: 2025-11-03T20:56:28.893Z

Link: CVE-2025-12659

cve-icon Vulnrichment

Updated: 2026-05-12T14:26:47.474Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-12T14:16:49.460

Modified: 2026-06-04T21:16:27.567

Link: CVE-2025-12659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-04T23:30:26Z

Weaknesses