Siemens Simcenter Femap Uninitialized Memory Vulnerability Leading to Remote Code Execution

Vulnerability

A vulnerability exists in Siemens Simcenter Femap, affecting all versions prior to V2512. The issue arises from uninitialized memory when the application parses specially crafted SLDPRT files. This vulnerability could enable an attacker to execute code within the context of the current process.

Impact

Exploitation of this vulnerability could result in remote code execution in the context of the current process.

Remediation

Users are advised to update to Simcenter Femap V2512 or later. For more information, visit the Siemens Support Center.

Added: Dec 12, 2025, 9:18 AM
Updated: Dec 12, 2025, 3:38 PM

Vulnerability Rating

Custom Algorithm
spread
2.4
impact
10.0
exploitability
4.4
remediation
7.7
relevance
1.3
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.