CVE-2026-23720
Siemens Simcenter Femap vulnerability analysis and mitigation

Overview

CVE-2026-23720 is an out-of-bounds read vulnerability affecting Siemens Simcenter Femap and Simcenter Nastran, both in all versions prior to V2512. The flaw exists in the NDB file parsing logic of these engineering simulation applications and can allow an attacker to execute arbitrary code in the context of the current process. It was published on February 10, 2026, with a patch made available the following day. The vulnerability carries a CVSS v3.1 base score of 7.3 (High) and a CVSS v4.0 base score of 7.3 (High) (Siemens CERT, Red Hat CVE).

Technical details

The root cause is classified as CWE-125 (Out-of-bounds Read), mapped to CAPEC-540 (Overread Buffers). When either Simcenter Femap or Simcenter Nastran parses a specially crafted NDB file, insufficient bounds checking allows a read operation to access memory outside the intended buffer, which can be leveraged to achieve code execution within the current process context. Exploitation requires local access, low privileges, and user interaction — specifically, a victim must open a malicious NDB file. No public proof-of-concept code has been identified (Siemens CERT, CISA ICS Advisory).

Impact

Successful exploitation allows an attacker to execute arbitrary code with the same privileges as the user running the affected application, potentially resulting in full system compromise. This includes unauthorized access to confidential data, modification of system files, and denial of service. Because Simcenter Femap and Nastran are used in engineering and industrial design environments, compromise could also expose sensitive intellectual property or simulation data (Siemens CERT, CISA ICS Advisory).

Exploitation steps

  1. Craft a malicious NDB file: Create a specially crafted NDB file that contains malformed data designed to trigger an out-of-bounds read during parsing by Simcenter Femap or Simcenter Nastran.
  2. Deliver the file to the target: Use social engineering, phishing, or supply chain methods to deliver the malicious NDB file to a user who has Simcenter Femap or Simcenter Nastran installed.
  3. Induce the victim to open the file: Convince the target user to open the crafted NDB file within the vulnerable application (user interaction is required).
  4. Trigger out-of-bounds read: Upon parsing, the application reads beyond the intended buffer boundary, potentially exposing memory contents or corrupting execution flow.
  5. Achieve code execution: Leverage the memory corruption to redirect execution flow and run arbitrary code in the context of the current user process, enabling further actions such as data exfiltration, persistence, or lateral movement (Siemens CERT, CISA ICS Advisory).

Indicators of compromise

  • File System: Unexpected or unsolicited NDB files received via email, file shares, or external media; NDB files with anomalous file sizes or structures.
  • Process: Unusual child processes spawned by Simcenter Femap or Simcenter Nastran executables (e.g., cmd.exe, powershell.exe, sh, curl, wget); application crashes or unexpected termination when opening NDB files.
  • Logs: Application crash logs or Windows Event Logs indicating access violations or memory errors in Simcenter Femap/Nastran processes; unexpected process creation events logged by endpoint detection tools.
  • Network: Outbound network connections initiated by Simcenter Femap or Nastran processes to unknown external IP addresses following file open events.

Mitigation and workarounds

Siemens has released patched versions addressing this vulnerability: users should upgrade Simcenter Femap and Simcenter Nastran to version V2512 or later. Until patching is complete, organizations should restrict users from opening NDB files from untrusted or unknown sources, and educate users about the risks of opening files from suspicious origins. Monitoring for unexpected process behavior in systems running these applications is also recommended (Siemens CERT, CISA ICS Advisory).

Community reactions

CISA published an ICS advisory (ICSA-26-048-01) covering this vulnerability, highlighting its relevance to industrial control system environments. Security news outlets including IT Security News and Cyble's weekly vulnerability report noted the flaw as part of broader ICS vulnerability roundups. Community coverage has been limited, consistent with the absence of public exploits or active exploitation (CISA ICS Advisory, Cyble Blog).

Additional resources


SourceThis report was generated using AI

Related Siemens Simcenter Femap vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2025-12659HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesMay 12, 2026
CVE-2026-23720HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2026-23719HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2026-23718HIGH7.3
  • Siemens Simcenter Femap logoSiemens Simcenter Femap
  • cpe:2.3:a:siemens:simcenter_femap
NoYesFeb 10, 2026
CVE-2025-40745MEDIUM6.3
  • Siemens Tecnomatix Plant Simulation logoSiemens Tecnomatix Plant Simulation
  • cpe:2.3:a:siemens:simcenter_femap
NoYesApr 14, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management