Siemens Solid Edge Out-of-Bounds Write Vulnerability in PRT File Parsing Allowing Code Execution

Vulnerability

A vulnerability exists in Siemens Solid Edge versions prior to V224.0 Update 14 and in Solid Edge SE2025 versions prior to V225.0 Update 6. The issue is an out-of-bounds write vulnerability that occurs while the application parses specially crafted PRT files. This vulnerability could enable an attacker to crash the application or execute code within the context of the current process.

Impact

Exploitation of this vulnerability could lead to application crashes or arbitrary code execution in the context of the current process.

Remediation

Users are advised to update Solid Edge to V224.0 Update 14 or V225.0 Update 6, depending on their current version. Additional guidance can be found in the Siemens Security Advisory SSA-541582.

Added: Oct 14, 2025, 10:18 AM
Updated: Oct 14, 2025, 10:18 AM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
10.0
exploitability
4.4
remediation
7.9
relevance
0.7
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.