Siemens NX Data Validation Vulnerability Leading to Arbitrary Code Execution

Vulnerability

A data validation vulnerability has been identified in Siemens NX, affecting all versions prior to V2512. This vulnerability could allow an attacker with local access to interfere with internal data during the PDF export process, potentially leading to arbitrary code execution.

Impact

Exploitation of this vulnerability could result in arbitrary code execution on the affected system.

Remediation

Users are advised to update to Siemens NX version V2512 or later. Additional product-specific recommendations can be found in the Siemens Security Advisory SSA-535115.

Added: Feb 10, 2026, 11:17 AM
Updated: Feb 10, 2026, 3:35 PM

Vulnerability Rating

Custom Algorithm
spread
4.2
impact
6.3
exploitability
2.3
remediation
7.9
relevance
2.7
threat
0.0
urgency
2.9
incentive
0.0

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.