CVE-2026-23715
Siemens Simcenter Femap vulnerability analysis and mitigation

Overview

CVE-2026-23715 is an out-of-bounds write vulnerability affecting Siemens Simcenter Femap and Simcenter Nastran during the parsing of specially crafted XDB files. All versions prior to V2512 of both products are affected. The vulnerability was published on February 10, 2026, with a patch advisory released by Siemens on February 11, 2026. It carries a CVSS v3.1 base score of 7.3 (High) (Siemens CERT, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-787 (Out-of-bounds Write), occurring when the affected applications parse maliciously crafted XDB files without proper bounds checking on memory write operations. An attacker must convince a local user with low privileges to open a specially crafted XDB file, triggering the out-of-bounds write condition. Successful exploitation allows arbitrary code execution within the context of the current process. No public proof-of-concept code has been identified at this time (Siemens CERT, CISA ICS Advisory).

Impact

Successful exploitation of this vulnerability can result in high impact to confidentiality, integrity, and availability of the affected system, as an attacker can execute arbitrary code in the context of the current user process. This could enable an attacker to access sensitive engineering or simulation data, modify files, or cause application crashes. The attack is locally scoped and does not affect systems beyond the compromised host, limiting lateral movement potential (Siemens CERT, Red Hat CVE).

Exploitation steps

  1. Craft malicious XDB file: An attacker creates a specially crafted XDB file designed to trigger an out-of-bounds write condition when parsed by Simcenter Femap or Simcenter Nastran.
  2. Deliver the file: The attacker delivers the malicious XDB file to a target user via email, file share, or other social engineering means, disguising it as a legitimate simulation or engineering file.
  3. User opens the file: The target user, running a vulnerable version of Simcenter Femap or Simcenter Nastran (prior to V2512), opens the crafted XDB file within the application.
  4. Trigger out-of-bounds write: The application's XDB parser writes data beyond the bounds of an allocated buffer, corrupting adjacent memory.
  5. Achieve code execution: The memory corruption is leveraged to redirect execution flow, allowing the attacker to execute arbitrary code in the context of the current user process (Siemens CERT, CISA ICS Advisory).

Indicators of compromise

  • Process: Unexpected child processes spawned by Simcenter Femap or Simcenter Nastran executables (e.g., cmd.exe, powershell.exe, or shell processes).
  • File System: Presence of unknown or suspicious XDB files in user download directories or shared drives; unexpected new files created in application directories after opening an XDB file.
  • Logs: Application crash logs or Windows Event Logs showing abnormal termination of Simcenter Femap or Nastran processes coinciding with XDB file open events.
  • Network: Unexpected outbound network connections originating from Simcenter Femap or Nastran processes following file open events.

Mitigation and workarounds

Siemens has released version V2512 of both Simcenter Femap and Simcenter Nastran to address this vulnerability. Users should upgrade to V2512 or later as the primary remediation. As a general workaround, users should avoid opening XDB files from untrusted or unknown sources, and organizations should apply the principle of least privilege to limit exposure. CISA also recommends minimizing network exposure for ICS/SCADA systems and following secure remote access practices (Siemens CERT, CISA ICS Advisory).

Community reactions

CISA published ICS Advisory ICSA-26-048-01 covering this and related Siemens Simcenter vulnerabilities, highlighting the risk to industrial control system environments. Security news outlets including IT Security News and Cyble's weekly vulnerability report noted the vulnerability as part of broader ICS security coverage. Community reaction has been limited given the low EPSS score and absence of public exploit code (CISA ICS Advisory, Cyble Blog).

Additional resources


SourceThis report was generated using AI

Related Siemens Simcenter Femap vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12659HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesMay 12, 2026
CVE-2026-23720HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2026-23719HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2026-23718HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2025-40745MEDIUM6.3
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:simcenter_femap
NoYesApr 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management