IM
IronMonkey Threat Research
‹ Back to ICS Advisories

SSA-584312: File Parsing Vulnerabilities in Simcenter Femap Before V2606 MP1

HIGH
CVSS 7.8
Date 2026-08-11T00:00:00+00:00
Source siemens-productcert
Published by Siemens ProductCERT

// Description

Simcenter Femap contains two file parsing vulnerabilities that could be triggered when the application reads files in BMP file format. If a user is tricked to open a malicious file with the affected application, this could lead the application to crash or potentially lead to arbitrary code execution. Siemens has released a new version for Simcenter Femap and recommends to update to the latest version.

// Vulnerabilities (2)

CVE ID CVSS Score Severity Description
CVE-2026-59700 7.8 high
CVE-2026-59700. The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.
CVE-2026-59701 7.8 high
CVE-2026-59701. The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.

// Remediations (1)

Patch: Update to V2606.0001 or later version
Update to V2606.0001 or later version

// References