VYPR
advisoryPublished Aug 13, 2026· 1 source

Siemens Parasolid Vulnerable to Out-of-Bounds Read Flaw

Siemens Parasolid software contains a critical out-of-bounds read vulnerability that could allow attackers to crash the application or execute arbitrary code.

Siemens has issued a security advisory detailing a critical vulnerability affecting its Parasolid software, a widely used geometric modeling kernel. The flaw, identified as CVE-2026-64629, is an out-of-bounds read vulnerability that can be triggered when the application processes specially crafted files in the X_T format.

An attacker could exploit this vulnerability by tricking a user into opening a malicious X_T file. Successful exploitation could lead to a denial-of-service condition, causing the application to crash. More critically, in certain scenarios, it could enable an attacker to execute arbitrary code within the context of the current process, potentially leading to a full system compromise.

The vulnerability specifically impacts Siemens Parasolid versions V38.0 prior to V38.0.235 and V38.1 prior to V38.1.230. These versions are used in various engineering and design applications across the critical manufacturing sector and are deployed globally.

Siemens has addressed this vulnerability by releasing updated versions of Parasolid. Users are strongly advised to update to V38.0.235 or later for V38.0, and V38.1.230 or later for V38.1. The company has provided links to the updated versions on its support portal.

The Common Vulnerability Scoring System (CVSS) v3 base score for this vulnerability is 7.8 (High), with a vector string of CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H. This indicates a significant risk, particularly due to the potential for arbitrary code execution with moderate user interaction required (opening a crafted file).

Siemens ProductCERT reported the vulnerability to CISA, which has republished the advisory to increase visibility. CISA recommends that organizations implement defensive measures to minimize exploitation risk, including network segmentation and limiting exposure of control system devices. While this vulnerability affects a software component, its widespread use in industrial design tools underscores the importance of timely patching and secure software development practices.

This incident highlights the ongoing challenges in securing complex software components that form the backbone of industrial design and engineering. As software becomes more intricate, the potential for subtle flaws like out-of-bounds reads to have severe consequences remains a persistent threat, emphasizing the need for continuous security vigilance and prompt remediation by vendors and users alike.

Synthesized by Vypr AI