Siemens Parasolid

Plan PatchCVSS 7.8ICS-CERT ICSA-26-225-10Aug 11, 2026
Siemens
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

Parasolid is affected by an out of bounds read vulnerability in X_T file parsing. When the application reads a malformed X_T format file, the vulnerability can cause the application to crash or allow arbitrary code execution. An attacker could leverage this by crafting a malicious X_T file and having a user open it.

What this means
What could happen
An attacker could crash Parasolid design software or execute arbitrary code by sending a malformed X_T CAD file, potentially compromising engineering workstations and the integrity of design files used in manufacturing or critical infrastructure systems.
Who's at risk
Engineering teams and manufacturing operations that use Siemens Parasolid for CAD design and modeling. This includes engineers opening design files from external vendors, suppliers, or email sources. Manufacturers that share designs with partners or customers are at particular risk if those files are returned with modifications.
How it could be exploited
An attacker crafts a malicious X_T file with out-of-bounds data. When an engineer or automated design tool opens this file in Parasolid, the vulnerability in the parser triggers, causing a memory read error that crashes the application or allows code execution on the engineering workstation.
Prerequisites
  • File must be in X_T format
  • User interaction required to open/parse the malicious file
  • Parasolid application must be installed and running
Low complexity exploitationUser interaction requiredAffects design/engineering systemsHigh CVSS score (7.8)
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
Parasolid V38.0 < V38.0.235< 38.0.23538.0.235
Parasolid V38.1 < V38.1.230< 38.1.23038.1.230
Remediation & Mitigation
0/4
Do now
0/1
WORKAROUNDImplement file validation controls to scan X_T files from untrusted sources before opening in Parasolid
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Parasolid V38.0 to version 38.0.235 or later
HOTFIXUpdate Parasolid V38.1 to version 38.1.230 or later
Long-term hardening
0/1
HARDENINGRestrict file sharing and email receipt of X_T files to trusted internal sources only
API: /api/v1/advisories/53632123-d8b4-44e0-9bb6-3518545967c4

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.

Siemens Parasolid | CVSS 7.8 - OTPulse