Description
A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.
Published: 2026-08-11
Score: 7.3 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an out-of-bounds read that occurs when Parasolid parses specially crafted X_T files. This flaw can allow an attacker to execute code in the context of the running process, potentially gaining full control over the system used by the application.

Affected Systems

Siemens Parasolid V38.0 versions earlier than 38.0.235 and Siemens Parasolid V38.1 versions earlier than 38.1.230 are affected. Users running these versions must determine if their workloads involve X_T file processing.

Risk and Exploitability

The CVSS score of 7.3 indicates a high severity vulnerability. EPSS data is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply a specially crafted X_T file to the application – the likely attack vector such as through a local file import is inferred from the description, not explicitly stated. If the application runs with elevated privileges, execution of malicious code would inherit those privileges. No public exploit has been reported at this time, but the flaw provides a clear foothold for attackers.

Generated by OpenCVE AI on August 11, 2026 at 23:48 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Siemens update that includes Parasolid V38.0.235 or later for Parasolid V38.0.
  • Apply the latest Siemens update that includes Parasolid V38.1.230 or later for Parasolid V38.1.
  • If an update cannot be applied immediately, restrict the ability to open or import X_T files to trusted users only and remove any known malicious X_T files.
  • As a temporary workaround, run the application with the minimum privileges required and disable the Parasolid component when handling untrusted file input.

Generated by OpenCVE AI on August 11, 2026 at 23:48 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 12 Aug 2026 00:15:00 +0000

Type Values Removed Values Added
Title Out-of-Bounds Read in Parasolid Leading to Code Execution

Tue, 11 Aug 2026 12:45:00 +0000

Type Values Removed Values Added
Description A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.
Weaknesses CWE-125
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: siemens

Published:

Updated: 2026-08-11T12:20:29.453Z

Reserved: 2026-07-20T13:21:17.902Z

Link: CVE-2026-64629

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-11T13:19:01.560

Modified: 2026-08-11T13:19:01.560

Link: CVE-2026-64629

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-12T00:00:03Z

Weaknesses