CVE-2025-12659
Siemens Simcenter Femap vulnerability analysis and mitigation

Overview

CVE-2025-12659 is a heap-based buffer overflow (memory corruption) vulnerability in Siemens Simcenter Femap's Datakit library that is triggered when parsing specially crafted IPT files, potentially allowing an attacker to execute arbitrary code in the context of the current process. It affects all versions of Simcenter Femap prior to V2512.0003. The vulnerability was disclosed on May 12, 2026, with CISA republishing the advisory on May 14, 2026. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 7.3 (High) (CISA Advisory, GitHub Advisory).

Technical details

The root cause is a heap-based buffer overflow (CWE-122) in the Datakit library used by Simcenter Femap for parsing IPT (PTC Creo/Pro/ENGINEER) file formats, resulting from insufficient validation of user-supplied data during file parsing. An attacker must craft a malicious IPT file and trick a user into opening it with the affected application; no authentication or elevated privileges are required beyond this social engineering step. The vulnerability was tracked internally as ZDI-CAN-27349 and ZDI-CAN-27389, and was reported by TrendAI Zero Day Initiative (CISA Advisory, ZDI Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the Simcenter Femap process, resulting in full compromise of confidentiality, integrity, and availability of the affected system at the user's privilege level. An attacker who achieves code execution could access sensitive engineering design data, modify or destroy project files, or use the compromised workstation as a pivot point for lateral movement within the organization's network. Given that Simcenter Femap is used in critical manufacturing environments worldwide, exploitation could have significant operational and intellectual property consequences (CISA Advisory, GitHub Advisory).

Exploitation steps

  1. Craft a malicious IPT file: Create a specially crafted IPT (PTC Creo/Pro/ENGINEER) file that triggers a heap-based buffer overflow in the Datakit library when parsed by Simcenter Femap. The overflow is caused by supplying data that exceeds the bounds of a heap-allocated buffer during IPT format processing.
  2. Deliver the malicious file: Use social engineering techniques to deliver the malicious IPT file to a target user — for example, via phishing email, a compromised file-sharing platform, or a malicious website that prompts the user to download and open the file.
  3. Trigger exploitation: When the victim opens the malicious IPT file in Simcenter Femap (versions prior to V2512.0003), the Datakit library processes the file and the heap overflow is triggered.
  4. Achieve code execution: The overflow corrupts heap memory in a controlled manner, enabling the attacker to redirect execution flow and run arbitrary code in the context of the Simcenter Femap process, with the same privileges as the logged-in user (CISA Advisory, ZDI Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by the Simcenter Femap process (e.g., cmd.exe, powershell.exe, bash, network utilities) following the opening of an IPT file.
  • File System: Unexpected files written to the Simcenter Femap installation directory or user temp directories shortly after opening an IPT file; presence of unfamiliar IPT files received via email or downloaded from external sources.
  • Network: Unusual outbound network connections originating from the Simcenter Femap process to external IP addresses, particularly after file open events.
  • Logs: Application crash logs or Windows Event Log entries (e.g., Event ID 1000/1001) indicating Simcenter Femap process faults or abnormal termination when opening IPT files; heap corruption error messages in application logs (CISA Advisory).

Mitigation and workarounds

Siemens has released a patched version and recommends updating Simcenter Femap to V2512.0003 or later, available via the Siemens support portal at https://support.sw.siemens.com/product/275652363/. As a general workaround, users should avoid opening IPT files from untrusted or unknown sources. Additionally, Siemens and CISA recommend minimizing network exposure for engineering workstations, isolating control system networks behind firewalls, and using VPNs for any required remote access (CISA Advisory, Siemens Advisory).

Community reactions

Siemens ProductCERT published advisory SSA-870926 addressing this vulnerability, and CISA republished it as ICS Advisory ICSA-26-134-05 on May 14, 2026, highlighting its relevance to critical manufacturing sectors worldwide. The vulnerability was reported by TrendAI Zero Day Initiative, which also published ZDI advisories (ZDI-26-317 and ZDI-26-316). Coverage has been limited to vulnerability tracking platforms and a small number of security news outlets (CISA Advisory, ZDI Advisory).

Additional resources


SourceThis report was generated using AI

Related Siemens Simcenter Femap vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12659HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesMay 12, 2026
CVE-2026-23720HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2026-23719HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2026-23718HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2025-40745MEDIUM6.3
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:simcenter_femap
NoYesApr 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management