
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-40829 is an uninitialized memory vulnerability in Siemens Simcenter Femap that allows arbitrary code execution when a user opens a specially crafted SLDPRT file. It affects all versions of Simcenter Femap prior to V2512. The vulnerability was disclosed by Siemens AG on December 12, 2025, with a ZDI advisory (ZDI-25-1124) published on December 17, 2025. It carries a CVSS v3.1 base score of 7.8 (High) and a CVSS v4.0 base score of 7.3 (High) (Siemens Advisory, ZDI Advisory).
The root cause is classified as CWE-908 (Use of Uninitialized Resource): the application fails to properly initialize memory before use when parsing SLDPRT (SolidWorks Part) files, leaving attacker-influenced data in memory that can be leveraged for code execution. Exploitation requires a local attack vector with no privileges required, but does require user interaction — specifically, a victim must open a maliciously crafted SLDPRT file within Simcenter Femap. The Zero Day Initiative tracked this issue as ZDI-CAN-27146 and published a corresponding advisory (ZDI Advisory, Siemens Advisory).
Successful exploitation allows an attacker to execute arbitrary code in the context of the current Simcenter Femap process, resulting in high impacts to confidentiality, integrity, and availability. An attacker could steal sensitive engineering or simulation data, modify project files, or disrupt application operations. Because the attack runs in the user's process context, the scope is limited to the affected workstation, though it could serve as a foothold for further lateral movement within an engineering network (Siemens Advisory, ZDI Advisory).
cmd.exe, powershell.exe, curl, or other shells/utilities not normally associated with the application).Siemens has released a patch in Simcenter Femap version V2512; all users should upgrade to V2512 or later immediately (Siemens Advisory). As interim mitigations, organizations should restrict file-opening permissions, implement strict file validation, and use application whitelisting to control which files can be opened in Simcenter Femap. Users should be trained not to open SLDPRT files from untrusted or unknown sources, and updated antivirus/file scanning tools should be deployed to detect potentially malicious files.
The vulnerability was reported through the Zero Day Initiative's coordinated disclosure program and published as ZDI-25-1124 on December 17, 2025, indicating responsible disclosure practices were followed (ZDI Advisory). No significant broader media coverage, notable researcher commentary, or social media discussion beyond standard CVE tracking and aggregator posts has been identified for this vulnerability.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."