
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-12659 is a heap-based buffer overflow (memory corruption) vulnerability in Siemens Simcenter Femap's Datakit library that is triggered when parsing specially crafted IPT files, potentially allowing an attacker to execute arbitrary code in the context of the current process. It affects all versions of Simcenter Femap prior to V2512.0003. The vulnerability was disclosed on May 12, 2026, with CISA republishing the advisory on May 14, 2026. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 7.3 (High) (CISA Advisory, GitHub Advisory).
The root cause is a heap-based buffer overflow (CWE-122) in the Datakit library used by Simcenter Femap for parsing IPT (PTC Creo/Pro/ENGINEER) file formats, resulting from insufficient validation of user-supplied data during file parsing. An attacker must craft a malicious IPT file and trick a user into opening it with the affected application; no authentication or elevated privileges are required beyond this social engineering step. The vulnerability was tracked internally as ZDI-CAN-27349 and ZDI-CAN-27389, and was reported by TrendAI Zero Day Initiative (CISA Advisory, ZDI Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the Simcenter Femap process, resulting in full compromise of confidentiality, integrity, and availability of the affected system at the user's privilege level. An attacker who achieves code execution could access sensitive engineering design data, modify or destroy project files, or use the compromised workstation as a pivot point for lateral movement within the organization's network. Given that Simcenter Femap is used in critical manufacturing environments worldwide, exploitation could have significant operational and intellectual property consequences (CISA Advisory, GitHub Advisory).
cmd.exe, powershell.exe, bash, network utilities) following the opening of an IPT file.Siemens has released a patched version and recommends updating Simcenter Femap to V2512.0003 or later, available via the Siemens support portal at https://support.sw.siemens.com/product/275652363/. As a general workaround, users should avoid opening IPT files from untrusted or unknown sources. Additionally, Siemens and CISA recommend minimizing network exposure for engineering workstations, isolating control system networks behind firewalls, and using VPNs for any required remote access (CISA Advisory, Siemens Advisory).
Siemens ProductCERT published advisory SSA-870926 addressing this vulnerability, and CISA republished it as ICS Advisory ICSA-26-134-05 on May 14, 2026, highlighting its relevance to critical manufacturing sectors worldwide. The vulnerability was reported by TrendAI Zero Day Initiative, which also published ZDI advisories (ZDI-26-317 and ZDI-26-316). Coverage has been limited to vulnerability tracking platforms and a small number of security news outlets (CISA Advisory, ZDI Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."