Siemens Solid Edge Out-of-Bounds Write Vulnerability in PRT File Parsing Allowing Code Execution

Vulnerability

A vulnerability exists in Siemens Solid Edge SE2024 (all versions prior to V224.0 Update 14) and SE2025 (all versions prior to V225.0 Update 6). The issue is an out-of-bounds write vulnerability that occurs when the application parses specially crafted PRT files. This vulnerability could enable an attacker to crash the application or execute code within the context of the current process.

Impact

Exploitation of this vulnerability could lead to application crashes or arbitrary code execution in the context of the current process.

Remediation

Users are advised to update Solid Edge to version V224.0 Update 14 or later for SE2024, and to version V225.0 Update 6 or later for SE2025. Additionally, Siemens recommends not opening untrusted PRT files in the affected applications.

Added: Oct 14, 2025, 10:18 AM
Updated: Oct 14, 2025, 10:18 AM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
7.5
exploitability
4.4
remediation
7.9
relevance
0.7
threat
0.0
urgency
2.9
incentive
0.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.