VYPR
advisoryPublished Aug 13, 2026· 1 source

Siemens Simcenter Femap Vulnerable to File Parsing Flaws, Enabling Code Execution

Siemens Simcenter Femap is affected by two critical file parsing vulnerabilities that could allow arbitrary code execution if users open malicious BMP files.

Siemens has issued a security advisory detailing two critical vulnerabilities within its Simcenter Femap software, specifically affecting versions prior to V2606.0001. These flaws, identified as CVE-2026-59700 and CVE-2026-59701, stem from issues in how the application parses Binary Large Object (BMP) image files.

The vulnerabilities are categorized as out-of-bounds reads, meaning that when Simcenter Femap encounters a specially crafted BMP file, it attempts to access memory locations beyond its allocated buffer. This can lead to application crashes, but more critically, it opens the door for attackers to execute arbitrary code within the context of the current process. The severity of these flaws is underscored by their CVSS v3 base score of 7.8, classifying them as HIGH.

Exploitation of these vulnerabilities requires a social engineering component. An attacker would need to trick a user into opening a malicious BMP file using an affected version of Simcenter Femap. Once the malicious file is opened, the out-of-bounds read vulnerability can be triggered, potentially leading to the execution of malicious code on the victim's system.

Siemens has addressed these critical vulnerabilities by releasing an update. Users of Simcenter Femap are strongly advised to update to version V2606.0001 or a later version to mitigate the risk. The company has provided a direct link to the update on its support portal.

These vulnerabilities were reported to CISA by Siemens ProductCERT. CISA, in turn, is republishing the advisory to increase visibility and encourage timely patching within critical infrastructure sectors, particularly those in critical manufacturing, where Simcenter Femap is deployed worldwide.

CISA recommends that organizations implement defensive measures to minimize the risk of exploitation. This includes minimizing network exposure for all control system devices and ensuring they are not accessible from the internet. Isolating control system networks behind firewalls and using secure remote access methods like VPNs are also crucial steps.

While the vulnerabilities are specific to file parsing of BMP images within Simcenter Femap, they highlight a persistent challenge in securing complex engineering software. Software that handles a wide variety of file formats often presents a larger attack surface, as each parser can be a potential entry point for malicious code.

Organizations are urged to perform thorough impact analyses and risk assessments before deploying any defensive measures. Proactive implementation of cybersecurity strategies, as outlined by CISA and Siemens' own operational guidelines for Industrial Security, is essential for protecting industrial control systems from such threats.

Synthesized by Vypr AI