Impact
The vulnerability is an out-of-bounds write that occurs while parsing specially crafted PSM files, which can lead to arbitrary code execution in the context of the current process. The flaw allows an attacker to provide a malicious file that triggers the vulnerability and gains the privileges of the running Solid Edge application.
Affected Systems
The issue affects Siemens Solid Edge SE2025 in all versions prior to V225.0 Update 15 and Solid Edge SE2026 in all versions prior to V226.0 Update 7. Users of these unpatched versions are at risk.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity, while the EPSS score is not available and the vulnerability is not listed in CISA KEV. The likely attack vector is an attacker who can supply a crafted PSM file, either through user interaction or a compromised file source. The vulnerability may be exploited locally, requiring the victim to open or process the malicious file.
OpenCVE Enrichment