Security & Threat Intelligence · 13.08.2026, 17:40 UTC
Siemens Parasolid
| Schweregrad | info |
|---|---|
| CVE | ↗ |
| Kategorie | Security & Threat Intelligence |
| Quelle | CISA ICS Advisories ↗ |
| Veröffentlicht | 13.08.2026 UTC |
Sicherheitsmeldung mit Schweregrad noch nicht bewertet. Betroffene Kennungen: CVE-2026-64629. Technische Details im Tab „Originaltext“; empfohlene Schritte in der Checkliste.
View CSAF Summary Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Parasolid are affected:
Parasolid V38.0 vers:intdot/<38.0.235 (CVE-2026-64629) Parasolid V38.1 vers:intdot/<38.1.230 (CVE-2026-64629)
CVSS Vendor Equipment Vulnerabilities
v3 7.8 Siemens Siemens Parasolid Out-of-bounds Read
Background
Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany
Vulnerabilities
Expand All +
CVE-2026-64629
The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. View CVE Details
Affected Products Siemens Parasolid
Vendor:Siemens Product Version:Parasolid V38.0 < V38.0.235, Parasolid V38.1 < V38.1.230 Product Status:known_affected
Remediations Vendor fixUpdate to V38.0.235 or later versionhttps://support.sw.siemens.com/product/258316782/ Vendor fixUpdate to V38.1.230 or later versionhttps://support.sw.siemens.com/product/258316782/
Relevant CWE: CWE-125 Out-of-bounds Read
Metrics
CVSS Version Base Score Base Severity Vector String
3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Acknowledgments
Siemens ProductCERT reported this vulnerability …