Impact
The vulnerability is an out-of-bounds read that occurs while Solid Edge parses specially crafted PAR files. This flaw is a CWE‑125 weakness and, when triggered, can give an attacker the ability to execute arbitrary code within the context of the Solid Edge process. The primary impact is the potential compromise of confidentiality, integrity, and availability of the affected system.
Affected Systems
Affected vendors and products include Siemens Solid Edge SE2025, all versions prior to V225.0 Update 15, and Siemens Solid Edge SE2026, all versions prior to V226.0 Update 7. These versions may be running in environments such as design teams or manufacturing systems where Solid Edge is used for 3‑D modeling.
Risk and Exploitability
The CVSS base score is 7.3, indicating a high severity. The EPSS score is not available and the vulnerability is not listed in the CISA KEV catalog. Based on the description, the likely attack vector is the execution of a malicious PAR file that an attacker can provide to a user running Solid Edge. The exploit requires the user to open or process a crafted file, so it is primarily a local threat that can happen via a social‑engineering attack or compromised file distribution. The impact, if successful, is high because it allows arbitrary code execution in the user’s session.
OpenCVE Enrichment