Impact
The vulnerability is an out‑of‑bounds write that occurs when Solid Edge parses specially crafted DFT files. This flaw allows an attacker to corrupt memory and execute arbitrary code within the context of the running Solid Edge process, potentially granting the attacker the same privileges as the application.
Affected Systems
Siemens Solid Edge SE2025 versions earlier than V225.0 Update 15 and Siemens Solid Edge SE2026 versions earlier than V226.0 Update 7 are affected. These versions are commonly deployed in engineering and design environments that process DFT files.
Risk and Exploitability
The CVSS score of 7.3 classifies the issue as high severity. EPSS data is not available, and the vulnerability is not listed in CISA KEV, suggesting that large‑scale exploitation has not yet been documented. The flaw is triggered by a specially crafted DFT file, so an attacker would need to supply that file. The likely attack vector is that the file is obtained remotely if the application accepts user uploads or network‑located files; this is inferred from the description and not directly stated. Successful exploitation depends on memory layout but offers the attacker the ability to run code with the privileges of Solid Edge.
OpenCVE Enrichment