Description
A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.
Published: 2026-08-11
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Simcenter Femap contains an out‑of‑bounds read that occurs while decoding BMP files. A specially crafted BMP can force the application to read memory beyond the correct bounds, enabling the attacker to execute arbitrary code with the same privileges as the running process. The flaw resides in the graphics parsing engine, so any user who opens a malicious BMP file can trigger the exploit. From the description, it is inferred that the attack vector involves supplying a specially crafted BMP file to trigger the out‑of‑bounds read.

Affected Systems

Siemens Simcenter Femap, all versions earlier than V2606.0001 are affected.

Risk and Exploitability

The CVSS score of 7.3 indicates moderate to high risk, and the vulnerability is not listed in the CISA KEV catalog. No EPSS score is available, so exploitation likelihood cannot be precisely quantified, but the missing public exploit code suggests a lower current threat level. Based on the description, it is inferred that the likely attack vector involves delivering a BMP file—whether through an email attachment, network share, or user‑initiated import—to activate the out‑of‑bounds read and potentially gain code execution within the application process.

Generated by OpenCVE AI on August 12, 2026 at 00:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the official Siemens update for Simcenter Femap version V2606.0001 or newer to remove the out‑of‑bounds read flaw identified as CWE‑125.
  • If an upgrade is not immediately possible, isolate the application in a sandboxed environment and restrict its access to untrusted BMP files, thereby minimizing the impact of the CWE‑125 exploitation.
  • Configure or modify the application to reject or sanitize BMP files from untrusted sources, or disable BMP handling altogether if not required for business operations.

Generated by OpenCVE AI on August 12, 2026 at 00:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:45:00 +0000

Type Values Removed Values Added
Title Simcenter Femap Out‑of‑Bounds Read During BMP Parsing Enables Remote Code Execution

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens simcenter Femap
Vendors & Products Siemens
Siemens simcenter Femap

Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Simcenter Femap (All versions < V2606.0001). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Siemens Simcenter Femap
cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-11T12:20:27.310Z

Reserved: 2026-07-06T15:11:37.370Z

Link: CVE-2026-59700

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-11T13:19:00.627

Modified: 2026-08-11T13:19:00.627

Link: CVE-2026-59700

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T00:30:03Z

Weaknesses