IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-138516: Out of Bounds Read Vulnerability in Parasolid X_T File Parsing

HIGH
CVSS 7.8
Date 2026-08-11T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions.

// Vulnerabilities (1)

CVE ID CVSS Score Severity Description
CVE-2026-64629 7.8 high
CVE-2026-64629. The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.

// Remediations (2)

Patch: Update to V38.1.230 or later version
Update to V38.1.230 or later version
Patch: Update to V38.0.235 or later version
Update to V38.0.235 or later version

// References