Impact
Solid Edge SE2025 and SE2026 contain an out‑of‑bounds read when parsing specially crafted PAR files. The flaw, classified as CWE‑125, can lead to execution of code in the context of the current process. An attacker who can provide a malicious PAR file (for example via local file selection or a compromised installation package) gains the authority of the user running Solid Edge.
Affected Systems
The vulnerability affects Siemens Solid Edge SE2025 in all versions older than V225.0 Update 15 and Siemens Solid Edge SE2026 in all versions older than V226.0 Update 7. These build identifiers correspond to the product releases that have not applied the out‑of‑bounds read fix.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity. No EPSS score is available, so the current exploitation probability cannot be quantified. The weakness is not present in the CISA KEV catalog. Exploitation requires a specially crafted PAR file to be parsed by Solid Edge, which typically means the attack vector is local or requires a privileged user to open the file. This makes the threat meaningful for environments where malicious files can be introduced, such as shared networks or compromised devices.
OpenCVE Enrichment