Siemens Parasolid Software Vulnerable to File-Based Attack, Update Urged
Siemens has disclosed a vulnerability in its Parasolid software, a modelling tool widely used in manufacturing and engineering design. The flaw, an out-of-bounds read issue, can be triggered when the application opens a file in the X_T format. If exploited, it could cause the software to crash or, more seriously, allow an attacker to run malicious code on the affected system.
The issue affects Parasolid versions V38.0 (prior to 38.0.235) and V38.1 (prior to 38.1.230). It has been rated with a CVSS score of 7.8, indicating a high severity level, though it requires a user to open a malicious file for the attack to succeed. Siemens has already released updated versions that resolve the vulnerability and is recommending that all users upgrade as soon as possible.
While Parasolid is primarily used in critical manufacturing environments worldwide, any Australian business using engineering or CAD software built on this platform should check with their software vendor to confirm whether they are affected. Because exploitation relies on opening a malicious file, staff awareness around file sources remains an important line of defence alongside patching.