Impact
The vulnerability is an out-of-bounds read (CWE-125) in Solid Edge’s DFT file parser. When a specially crafted DFT file is parsed, the application may read memory beyond the intended bounds, allowing an attacker to influence code execution in the same security context as the running process. This results in loss of confidentiality, integrity and availability of the affected system.
Affected Systems
Siemens Solid Edge SE2025 versions earlier than V225.0 Update 15 and Siemens Solid Edge SE2026 versions earlier than V226.0 Update 7 are affected. Any system running these older releases is vulnerable when a malicious DFT file is opened or imported.
Risk and Exploitability
The CVSS score of 7.3 classifies this vulnerability as high severity. No EPSS data is available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog, indicating no confirmed exploitation at the time of assessment. The likely attack vector involves an attacker delivering a specially crafted DFT file, which a user may open locally or via a file share; this inference is drawn from the description that the flaw occurs while parsing DFT files.
OpenCVE Enrichment