CVE-2026-23717
Siemens Simcenter Femap vulnerability analysis and mitigation

Overview

CVE-2026-23717 is an out-of-bounds read vulnerability affecting Siemens Simcenter Femap and Simcenter Nastran, both in all versions prior to V2512. The flaw exists in the XDB file parsing logic of these engineering simulation applications and could allow an attacker to execute arbitrary code in the context of the current process. It was published on February 10, 2026, with a patch advisory released by Siemens on February 11, 2026. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) and a CVSS v4.0 base score of 7.3 (High) (Siemens CERT, Red Hat CVE).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read), triggered during the parsing of specially crafted XDB files within Simcenter Femap and Simcenter Nastran. When a malicious XDB file is opened, the application reads memory beyond the bounds of an allocated buffer, which can be leveraged to achieve arbitrary code execution in the context of the running process. Exploitation requires local access and user interaction — specifically, a user must be tricked into opening a maliciously crafted XDB file. No public proof-of-concept code has been identified (Siemens CERT, CISA ICS Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the privileges of the user running the affected application, resulting in high confidentiality, integrity, and availability impacts. This could lead to unauthorized access to sensitive engineering data, modification or destruction of project files, and disruption of application availability. Because Simcenter Femap and Nastran are used in industrial and engineering environments, compromise could affect sensitive intellectual property or safety-critical simulation data (Siemens CERT).

Exploitation steps

  1. Craft malicious XDB file: An attacker creates a specially crafted XDB file designed to trigger an out-of-bounds read when parsed by Simcenter Femap or Simcenter Nastran.
  2. Social engineering: The attacker delivers the malicious XDB file to a target user via email, file share, or other means, disguising it as a legitimate engineering project file.
  3. User opens the file: The victim opens the malicious XDB file using a vulnerable version of Simcenter Femap or Simcenter Nastran (any version prior to V2512).
  4. Out-of-bounds read triggered: The application's XDB parser reads beyond the allocated buffer boundary, potentially exposing memory contents or corrupting control flow data.
  5. Code execution: The memory corruption is leveraged to redirect execution flow, allowing the attacker to execute arbitrary code with the privileges of the current user process (Siemens CERT, CISA ICS Advisory).

Indicators of compromise

  • File System: Unexpected or unsolicited XDB files received via email or file shares; newly created or modified files in Simcenter Femap/Nastran working directories following file open events.
  • Process: Unusual child processes spawned by the Simcenter Femap or Nastran application process (e.g., cmd.exe, powershell.exe, sh, network utilities); application crashes or unexpected termination after opening an XDB file.
  • Logs: Application crash logs or Windows Event Logs indicating access violations or memory errors in Simcenter Femap/Nastran processes; unexpected process creation events logged by endpoint detection tools shortly after XDB file open events.
  • Network: Unexpected outbound network connections originating from the Simcenter Femap or Nastran process following file parsing activity.

Mitigation and workarounds

Siemens has released version V2512 for both Simcenter Femap and Simcenter Nastran, which resolves this vulnerability. Users should upgrade to V2512 or later as the primary remediation. As an interim measure, users should avoid opening XDB files from untrusted or unknown sources, and organizations should implement application whitelisting and restrict access to XDB files from external origins. The full patch advisory is available from Siemens ProductCERT (Siemens CERT, CISA ICS Advisory).

Community reactions

CISA published an ICS advisory (ICSA-26-048-01) covering this vulnerability, highlighting its relevance to industrial control system environments (CISA ICS Advisory). Security news outlets including IT Security News and RedPacket Security reported on the vulnerability shortly after disclosure, though no significant researcher commentary or broader community debate has been observed. Overall community reaction has been muted, consistent with the low EPSS score and absence of public exploit code.

Additional resources


SourceThis report was generated using AI

Related Siemens Simcenter Femap vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12659HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesMay 12, 2026
CVE-2026-23720HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2026-23719HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2026-23718HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2025-40745MEDIUM6.3
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:simcenter_femap
NoYesApr 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management