Impact
The vulnerability is an out‑of‑bounds read when parsing specially crafted XDB files. This defect allows an attacker to govern arbitrary code execution inside the context of the application process, thereby enabling compromise of the system.
Affected Systems
Siemens Simcenter Femap and Simcenter Nastran are affected. All releases prior to version V2512 contain the flaw.
Risk and Exploitability
The CVSS score of 7.3 marks this issue as high severity. The EPSS score under 1 percent indicates a low exploitation probability at this time. It is not listed in CISA’s KEV catalog. The most likely attack vector is via a malicious XDB file supplied to the vulnerable application, resulting in code execution constrained to the privileges under which the application runs.
OpenCVE Enrichment