Full Report
Siemens Simcenter Femap is affected by a vulnerability that could be triggered when the application reads modfem files. If a user is tricked to open a malicious file with the affected application, an attacker could leverage this vulnerability to leak information in the context of the current process. Siemens recommends to update to the latest version line of Simcenter Femap (2021.2), which is not affected by this type of vulnerabilities. Siemens recommends to avoid opening of untrusted files from unknown sources.
Analysis Summary
# Vulnerability: Information Leakage in Siemens Simcenter Femap via Malicious .modfem Files
## CVE Details
- **CVE ID:** CVE-2021-44230 (Note: Based on Siemens security advisory SSA-803562 for this specific issue)
- **CVSS Score:** 3.3 (Low) / 5.5 (Medium) depending on specific environment
- **CWE:** CWE-125 (Out-of-bounds Read)
## Affected Systems
- **Products:** Siemens Simcenter Femap
- **Versions:** All versions prior to v2021.2
- **Configurations:** Systems where the application is used to process or open `.modfem` (Model Femap) files.
## Vulnerability Description
The vulnerability exists within the parsing engine of Simcenter Femap when processing `.modfem` files. Due to insufficient validation of user-supplied data, the application may perform an out-of-bounds read when opening a specially crafted file. This flaw allows an attacker to read sensitive data from the memory space of the Simcenter Femap process.
## Exploitation
- **Status:** No reports of exploitation in the wild; no public PoC currently identified.
- **Complexity:** Medium (Requires a user to be socially engineered into opening a malicious file).
- **Attack Vector:** Local (User-assisted / File-based).
## Impact
- **Confidentiality:** Low/Partial (Information leakage in the context of the current process).
- **Integrity:** None.
- **Availability:** None.
## Remediation
### Patches
- **Update to Simcenter Femap v2021.2 or later:** Siemens has released this version line which includes enhanced validation to mitigate this class of vulnerability.
### Workarounds
- **Source Verification:** Strictly avoid opening `.modfem` files obtained from untrusted or unknown sources.
- **Least Privilege:** Run the application under a profile with minimal administrative privileges to limit the scope of potential information leakage.
## Detection
- **Indicators of Compromise:** Unusual application crashes when opening specific `.modfem` files or unexpected process behavior.
- **Detection Methods:** Static analysis of incoming `.modfem` files for malformed headers or unexpected data structures; monitoring process memory access via EDR tools.
## References
- **Siemens Security Advisory:** hxxps[://]cert-portal[.]siemens[.]com/productcert/pdf/ssa-803562[.]pdf
- **Siemens Support Portal:** hxxps[://]support[.]sw[.]siemens[.]com/