Impact
Simcenter Femap contains an out‑of‑bounds read that occurs while decoding BMP files. A specially crafted BMP can force the application to read memory beyond the correct bounds, enabling the attacker to execute arbitrary code with the same privileges as the running process. The flaw resides in the graphics parsing engine, so any user who opens a malicious BMP file can trigger the exploit. From the description, it is inferred that the attack vector involves supplying a specially crafted BMP file to trigger the out‑of‑bounds read.
Affected Systems
Siemens Simcenter Femap, all versions earlier than V2606.0001 are affected.
Risk and Exploitability
The CVSS score of 7.3 indicates moderate to high risk, and the vulnerability is not listed in the CISA KEV catalog. No EPSS score is available, so exploitation likelihood cannot be precisely quantified, but the missing public exploit code suggests a lower current threat level. Based on the description, it is inferred that the likely attack vector involves delivering a BMP file—whether through an email attachment, network share, or user‑initiated import—to activate the out‑of‑bounds read and potentially gain code execution within the application process.
OpenCVE Enrichment