Siemens Solid Edge Out-of-Bounds Read Vulnerability Allowing Code Execution
Vulnerability
A vulnerability exists in Siemens Solid Edge SE2025, all versions prior to V225.0 Update 5. The issue involves an out-of-bounds read past the end of an allocated structure when the application parses specially crafted PAR files. This vulnerability could enable an attacker to execute code within the context of the current process.
Impact
Exploitation of this vulnerability could lead to arbitrary code execution in the context of the current process.
Remediation
Users are advised to update Solid Edge to version V225.0 Update 5 or later. For those using Solid Edge SE2025, all versions prior to V225.0 Update 5 are affected. Specific workarounds include not opening untrusted PAR files in the affected application.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
