Impact
An out-of-bounds write vulnerability exists in the parsing of XDB files for both Simcenter Femap and Simcenter Nastran, enabling an attacker who can supply a specially crafted XDB file to execute arbitrary code in the process context of the application. The flaw allows memory corruption that can overwrite executable code or data, thereby compromising confidentiality, integrity, and availability of the affected system.
Affected Systems
Siemens Simcenter Femap (all versions earlier than 2512) and Siemens Simcenter Nastran (all versions earlier than 2512) are affected. The vulnerability is limited to these products; no other Siemens applications are impacted.
Risk and Exploitability
With a CVSS score of 7.3, this is a high-severity flaw. The EPSS score is below 1%, indicating a low probability of exploitation at present, and it is not listed in the CISA KEV catalog. The likely attack vector is remote, inferred from the fact that a malicious XDB file would need to be provided to the application; if the application processes such a file, code execution occurs under the privileges of the running process, potentially giving the attacker system-level access.
OpenCVE Enrichment