Siemens Solid Edge Out-of-Bounds Read Vulnerability in PAR File Parsing

Vulnerability

A vulnerability exists in Siemens Solid Edge SE2025, all versions prior to V225.0 Update 5, allowing for an out-of-bounds read past the end of an allocated structure. This issue arises while parsing specially crafted PAR files, potentially enabling an attacker to execute code within the context of the current process.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution in the context of the user running the application.

Remediation

Users are advised to update Solid Edge to version V225.0 Update 5 or later. Additionally, do not open untrusted PAR files in the affected application.

Added: Jul 8, 2025, 11:31 AM
Updated: Jul 8, 2025, 11:31 AM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
4.4
remediation
0.0
relevance
0.2
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.