Description
A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.
Published: 2026-08-11
Score: 7.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The flaw is a stack overflow triggered by parsing specially crafted strings passed to a Simcenter Nastran or Simcenter Femap binary. Exploitation would allow an attacker to run arbitrary code within the context of the process, compromising confidentiality, integrity and availability of the affected system. The vulnerability is indexed as CWE-121.

Affected Systems

Siemens Simcenter Nastran and Simcenter Femap, all versions prior to V2606. The flaw affects all builds earlier than the 2606 release.

Risk and Exploitability

The CVSS score of 7.3 indicates high severity. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA KEV, implying no known widespread exploitation yet. However, due to the ability to execute code in the current process and lack of public exploits, the risk remains significant, especially in environments where the application runs with elevated privileges. The attack vector appears to be local or remote depending on how the application receives inputs; the description implies the vulnerability can be triggered through input arguments to the binary.

Generated by OpenCVE AI on August 13, 2026 at 10:46 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Simcenter Nastran and Femap to version V2606 or later to remove the stack overflow vulnerability.
  • If upgrading is not immediately feasible, restrict execution of the vulnerable binary to trusted accounts and enforce least‑privilege execution.
  • Monitor system logs for abnormal process activity or unexpected execution patterns that could indicate an attempt to exploit the overflow.

Generated by OpenCVE AI on August 13, 2026 at 10:46 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 13 Aug 2026 11:15:00 +0000

Type Values Removed Values Added
Title Stack Overflow Vulnerability in Simcenter Nastran Enables Remote Code Execution

Thu, 13 Aug 2026 09:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process. A vulnerability has been identified in Simcenter Femap (All versions < V2606), Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.

Tue, 11 Aug 2026 23:45:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens simcenter Nastran
Vendors & Products Siemens
Siemens simcenter Nastran

Tue, 11 Aug 2026 23:30:00 +0000

Type Values Removed Values Added
Title Stack Overflow Vulnerability in Simcenter Nastran Enables Remote Code Execution

Tue, 11 Aug 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Simcenter Nastran (All versions < V2606). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.
Weaknesses CWE-121
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Simcenter Nastran
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-13T09:28:24.875Z

Reserved: 2026-07-02T13:41:41.932Z

Link: CVE-2026-59086

cve-icon Vulnrichment

Updated: 2026-08-11T14:49:50.452Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-08-11T13:19:00.333

Modified: 2026-08-28T19:03:37.837

Link: CVE-2026-59086

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-13T11:00:12Z

Weaknesses
  • CWE-121

    Stack-based Buffer Overflow