Impact
This vulnerability is a heap-based buffer overflow that occurs while the application parses specially crafted NDB files. The flaw can allow an attacker to execute arbitrary code in the context of the running process. It is identified as a CWE‑122 weakness.
Affected Systems
The affected software is Siemens Simcenter Femap and Simcenter Nastran, all releases prior to version V2512.
Risk and Exploitability
The CVSS score is 7.3, indicating a high severity. However, the EPSS score is below 1%, suggesting that the likelihood of exploitation is very low. The vulnerability is not listed in the CISA KEV catalog. The likely attack vector is file-based: an attacker supplies a malicious NDB file that the victim opens, giving the attacker remote code execution capabilities within the victim’s process.
OpenCVE Enrichment