Siemens Solid Edge Software Vulnerable to Malicious File Attacks
Siemens has disclosed several vulnerabilities affecting its Solid Edge CAD software, used widely in engineering and manufacturing environments. The flaws are triggered when the application opens specially crafted PAR, PSM, or DFT files, and include out-of-bounds read/write and use-after-free issues. If exploited, an attacker could crash the software or potentially execute arbitrary code on the affected system.
The issues affect Solid Edge SE2025 versions before 225.0.15 and SE2026 versions before 226.0.7, carrying a CVSS severity score of 7.8 (high). Siemens has released updated versions that address these vulnerabilities, and businesses using Solid Edge should apply the latest updates as soon as possible.
While this issue primarily affects engineering and manufacturing firms using Solid Edge, it's a reminder that specialised design and engineering software can be just as vulnerable as everyday business applications, especially when opening files from external or unverified sources.