Full Report
Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.
Analysis Summary
# Vulnerability: Out of Bounds Read in Parasolid X_T File Parsing
## CVE Details
- **CVE ID:** CVE-2026-64629
- **CVSS Score:** 7.8 (High) - CVSS v3.1 / 7.3 (High) - CVSS v4.0
- **CWE:** CWE-125 (Out-of-bounds Read)
## Affected Systems
- **Products:** Siemens Parasolid (Geometric modeling kernel)
- **Versions:**
- Parasolid V38.0: All versions prior to V38.0.235
- Parasolid V38.1: All versions prior to V38.1.230
- **Configurations:** Systems utilizing the Parasolid kernel to parse or process X_T (Parasolid XT) format files.
## Vulnerability Description
A vulnerability exists in the way affected versions of Parasolid parse specially crafted files in the X_T format. Due to an out-of-bounds read flaw, the application may access memory outside the intended buffer. While primarily a read vulnerability, the memory corruption associated with this flaw can be leveraged to crash the application (Denial of Service) or potentially achieve arbitrary code execution within the context of the current process.
## Exploitation
- **Status:** Not currently reported as exploited in the wild; no public PoC provided in advisory.
- **Complexity:** Low (CVSS 3.1) / High (CVSS 4.0 - specifically regarding Attack Technology/Complexity).
- **Attack Vector:** Local (Requires a user to open a malicious file).
## Impact
- **Confidentiality:** High (Potential to read sensitive memory or execute code).
- **Integrity:** High (Potential for arbitrary code execution).
- **Availability:** High (Application crash or process takeover).
## Remediation
### Patches
Siemens recommends updating to the following versions or later:
- **Parasolid V38.0:** Update to **V38.0.235**
- **Parasolid V38.1:** Update to **V38.1.230**
### Workarounds
- **General Security Best Practices:** Siemens recommends protecting network access and operating within protected IT environments according to their operational guidelines.
- **User Caution:** Avoid opening X_T files from untrusted or unknown sources.
## Detection
- **Indicators of Compromise:** Unusual application crashes when processing X_T files; unexpected outbound network traffic if code execution is achieved.
- **Detection Methods:** Security teams should use software inventory tools to identify vulnerable versions of Parasolid integrated into their CAD/CAM/CAE software suites.
## References
- **Vendor Advisory:** hxxps://cert-portal.siemens.com/productcert/html/ssa-138516.html
- **Siemens Support Portal:** hxxps://support.sw.siemens.com/product/258316782/
- **Industrial Security Guidelines:** hxxps://www.siemens.com/cert/operational-guidelines-industrial-security