Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process.

Project Subscriptions

Vendors Products
Siemens Subscribe
Simcenter Femap Subscribe
Advisories

No advisories yet.

Fixes

Solution

Update to V2512.0003 or later version https://support.sw.siemens.com/product/275652363/


Workaround

No workaround given by the vendor.

History

Thu, 04 Jun 2026 21:00:00 +0000

Type Values Removed Values Added
Description The affected applications contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-27349, ZDI-CAN-27389) Siemens Simcenter Femap contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process.
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H'}


Tue, 12 May 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 12 May 2026 15:00:00 +0000

Type Values Removed Values Added
First Time appeared Siemens
Siemens simcenter Femap
Vendors & Products Siemens
Siemens simcenter Femap

Tue, 12 May 2026 13:30:00 +0000

Type Values Removed Values Added
Description The affected applications contains a memory corruption vulnerability while parsing specially crafted IPT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-27349, ZDI-CAN-27389)
Title Heap-based buffer overflow in Siemens Simcenter Femap
Weaknesses CWE-122
References
Metrics cvssV4_0

{'score': 7.3, 'vector': 'CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2026-06-04T20:22:03.369Z

Reserved: 2025-11-03T20:56:28.893Z

Link: CVE-2025-12659

cve-icon Vulnrichment

Updated: 2026-05-12T14:26:47.474Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-05-12T14:16:49.460

Modified: 2026-06-04T21:16:27.567

Link: CVE-2025-12659

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-04T23:30:26Z

Weaknesses