Impact
The flaw is a stack overflow triggered by parsing specially crafted strings passed to a Simcenter Nastran or Simcenter Femap binary. Exploitation would allow an attacker to run arbitrary code within the context of the process, compromising confidentiality, integrity and availability of the affected system. The vulnerability is indexed as CWE-121.
Affected Systems
Siemens Simcenter Nastran and Simcenter Femap, all versions prior to V2606. The flaw affects all builds earlier than the 2606 release.
Risk and Exploitability
The CVSS score of 7.3 indicates high severity. The EPSS score of < 1% indicates a very low but nonzero probability of exploitation, and the vulnerability is not listed in CISA KEV, implying no known widespread exploitation yet. However, due to the ability to execute code in the current process and lack of public exploits, the risk remains significant, especially in environments where the application runs with elevated privileges. The attack vector appears to be local or remote depending on how the application receives inputs; the description implies the vulnerability can be triggered through input arguments to the binary.
OpenCVE Enrichment