Impact
The vulnerability is an out-of-bounds read that occurs when Parasolid parses specially crafted X_T files. This flaw can allow an attacker to execute code in the context of the running process, potentially gaining full control over the system used by the application.
Affected Systems
Siemens Parasolid V38.0 versions earlier than 38.0.235 and Siemens Parasolid V38.1 versions earlier than 38.1.230 are affected. Users running these versions must determine if their workloads involve X_T file processing.
Risk and Exploitability
The CVSS score of 7.3 indicates a high severity vulnerability. EPSS data is not available, so the current exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers would need to supply a specially crafted X_T file to the application – the likely attack vector such as through a local file import is inferred from the description, not explicitly stated. If the application runs with elevated privileges, execution of malicious code would inherit those privileges. No public exploit has been reported at this time, but the flaw provides a clear foothold for attackers.
OpenCVE Enrichment