CVE-2026-23718
Siemens Simcenter Femap vulnerability analysis and mitigation

Overview

CVE-2026-23718 is an out-of-bounds read vulnerability affecting Siemens Simcenter Femap and Simcenter Nastran (all versions prior to V2512). The flaw exists in the NDB file parsing logic of both applications and can allow an attacker to execute arbitrary code in the context of the current process. It was published on February 10, 2026, with a patch advisory released by Siemens CERT on February 11, 2026. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) (Siemens CERT, CISA ICS Advisory).

Technical details

The vulnerability is classified as CWE-125 (Out-of-bounds Read), triggered during the parsing of specially crafted NDB files within Simcenter Femap and Simcenter Nastran. An attacker must convince a local user to open a malicious NDB file, making user interaction a required precondition; the attacker also needs low-level local privileges. The out-of-bounds read condition can be leveraged to achieve code execution within the context of the running process, potentially enabling further exploitation (Siemens CERT, CISA ICS Advisory). No public proof-of-concept code has been identified at this time (Red Hat CVE).

Impact

Successful exploitation results in high confidentiality, integrity, and availability impact within the scope of the affected process. An attacker who tricks a user into opening a malicious NDB file can execute arbitrary code with the privileges of that user, potentially enabling unauthorized access to sensitive engineering data, modification of simulation configurations, and disruption of application availability. The attack is locally scoped and does not directly affect other systems, but could serve as a foothold for further lateral movement if the compromised user account has broader network access (Siemens CERT, CISA ICS Advisory).

Exploitation steps

  1. Craft malicious NDB file: An attacker creates a specially crafted NDB file designed to trigger an out-of-bounds read condition during parsing by Simcenter Femap or Simcenter Nastran.
  2. Deliver the file: The attacker delivers the malicious NDB file to a target user via email, shared network drive, or other social engineering means, disguising it as a legitimate simulation or analysis file.
  3. User opens the file: The target user opens the malicious NDB file using Simcenter Femap or Simcenter Nastran on a local workstation.
  4. Trigger out-of-bounds read: The application's NDB parser reads beyond the allocated buffer boundary, potentially exposing memory contents or corrupting adjacent memory.
  5. Achieve code execution: The memory corruption condition is exploited to redirect execution flow, allowing the attacker to execute arbitrary code with the privileges of the user running the application (Siemens CERT, CISA ICS Advisory).

Indicators of compromise

  • File System: Presence of unexpected or unsolicited NDB files in user download directories, email attachments, or shared drives; newly created executables or scripts in user-writable directories following NDB file access.
  • Process: Unusual child processes spawned by Simcenter Femap or Simcenter Nastran (e.g., cmd.exe, powershell.exe, sh) shortly after opening an NDB file; application crashes or abnormal termination events.
  • Logs: Application crash logs or Windows Event Logs (Event ID 1000/1001) referencing Simcenter Femap or Nastran process faults; unexpected access violations recorded in system event logs.
  • Network: Unexpected outbound network connections originating from the Simcenter Femap or Nastran process to external IP addresses following file open events.

Mitigation and workarounds

Siemens has released version V2512 for both Simcenter Femap and Simcenter Nastran, which addresses this vulnerability. Users should upgrade to V2512 or later as the primary remediation step. As an interim workaround, organizations should restrict or disable the opening of NDB files from untrusted or unknown sources, implement application whitelisting, and educate users about the risks of opening files from suspicious origins. Monitoring for unusual file handling activities involving NDB files is also recommended (Siemens CERT, CISA ICS Advisory).

Community reactions

CISA published ICS Advisory ICSA-26-048-01 in response to this vulnerability, highlighting its relevance to industrial control system environments and recommending prompt patching (CISA ICS Advisory). Security news outlets including IT Security News and Red Packet Security covered the disclosure, noting the availability of the vendor patch (Red Packet Security). Community reaction has been measured, consistent with the low EPSS score and absence of active exploitation.

Additional resources


SourceThis report was generated using AI

Related Siemens Simcenter Femap vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12659HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesMay 12, 2026
CVE-2026-23720HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2026-23719HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2026-23718HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2025-40745MEDIUM6.3
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:simcenter_femap
NoYesApr 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management