Impact
An application use‑after‑free flaw in Siemens Solid Edge SE2025 and SE2026 can be triggered by parsing a specially crafted DFT file, allowing an attacker to run arbitrary code within the user’s process context. The weakness falls under CWE‑416 and can compromise confidentiality, integrity, and availability of the affected system.
Affected Systems
The vulnerability affects Siemens Solid Edge SE2025 versions earlier than V225.0 Update 15 and Siemens Solid Edge SE2026 versions earlier than V226.0 Update 7. Users running these product releases are at risk when handling untrusted DFT files.
Risk and Exploitability
The CVSS score is 7.3, indicating a high severity risk. EPSS is not available and the vulnerability is not listed in CISA KEV. The likely attack vector is local or remote supply‑chain delivery of a malicious DFT file; after the use‑after‑free can be exploited to attain code execution.
OpenCVE Enrichment