Impact
An out‑of‑bounds read flaw exists in the BMP parsing routine of Siemens Simcenter Femap, allowing an attacker to read erroneous memory locations and potentially execute arbitrary code within the context of the running process. This is a classic CWE‑125 vulnerability that can compromise confidentiality, integrity, and availability by letting an attacker gain the same privileges as the application.
Affected Systems
All Siemens Simcenter Femap versions earlier than V2606.0001 are affected. Users should verify the installed version and consider upgrading to at least V2606.0001.
Risk and Exploitability
The CVSS score of 7.3 indicates a high risk. No EPSS score is available, and the vulnerability is not listed in CISA KEV, suggesting no confirmed widespread exploitation yet. The likely attack vector is local or remote delivery of a malicious BMP file that the application parses, which can then trigger the out‑of‑bounds read and lead to code execution.
OpenCVE Enrichment