Zero-DayОригинал на английском
Siemens Solid Edge
Русский перевод готовится и скоро появится на сайте. Пока доступен оригинал на английском.
View CSAF Summary Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has rel
CISA Alerts··3 мин чтения
View CSAF Summary Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Solid Edge are affected: Solid Edge SE2025 vers:intdot/<225.0.15 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064) Solid Edge SE2026 vers:intdot/<226.0.7 (CVE-2026-50058, CVE-2026-50059, CVE-2026-50060, CVE-2026-50061, CVE-2026-50062, CVE-2026-50063, CVE-2026-50064) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens Solid Edge Out-of-bounds Read, Out-of-bounds Write, Use After Free Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-50058 The affected applications contains an out of bounds read vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Solid Edge Vendor: Siemens Product Version: Solid Edge SE2025 < V225.0.15, Solid Edge SE2026 < V226.0.7 Product Status: known_affected Remediations Vendor fix Update to V225.0 Update 15 or later version https://support.sw.siemens.com/product/246738425/ Vendor fix Update to V226.0 Update 7 or later version https://support.sw.siemens.com/product/246738425/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2026-50059 The affected applications contains an out of bounds write vulnerability while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Solid Edge Vendor: Siemens Product Version: Solid Edge SE2025 < V225.0.15, Solid Edge SE2026 < V226.0.7 Product Status: known_affected Remediations Vendor fix Update to V225.0 Update 15 or later version https://support.sw.siemens.com/product/246738425/ Vendor fix Update to V226.0 Update 7 or later version https://support.sw.siemens.com/product/246738425/ Relevant CWE: CWE-787 Out-of-bounds Write Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2026-50060 The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Solid Edge Vendor: Siemens Product Version: Solid Edge SE2025 < V225.0.15, Solid Edge SE2026 < V226.0.7 Product Status: known_affected Remediations Vendor fix Update to V225.0 Update 15 or later version https://support.sw.siemens.com/product/246738425/ Vendor fix Update to V226.0 Update 7 or later version https://support.sw.siemens.com/product/246738425/ Relevant CWE: CWE-416 Use After Free Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H CVE-2026-50061 The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Solid Edge Vendor: Siemens Product Version: Solid Edge SE2025 < V225.0.15, Solid Edge SE2026 < V226.0.7 Product Status: known_affected Remediations Vendor fix Update to V225.0 Update 15 or later version https://support.sw.siemens.com/product/246738425/ Vendor fix Update to V226.0 Update 7 or later version https://support.sw.siemens.com/product/246738425/
