Siemens Simcenter Femap

Plan PatchCVSS 7.8ICS-CERT ICSA-26-225-11Aug 11, 2026
Siemens
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary

Simcenter Femap before version 2606.0001 contains file parsing vulnerabilities in BMP file handling. When a user opens a specially crafted malicious BMP file, the application may crash or allow arbitrary code execution. The vulnerability is triggered by malformed BMP file content during parsing.

What this means
What could happen
An attacker could trick a user into opening a malicious BMP file in Simcenter Femap, causing the application to crash or potentially allowing code execution on the engineering workstation with the user's privileges.
Who's at risk
Organizations using Simcenter Femap for finite element analysis and CAD design work on engineering workstations are affected. This includes mechanical engineering departments, product design teams, and any engineering contractors using Femap for structural analysis or simulation.
How it could be exploited
An attacker crafts a malicious BMP file and tricks a user (e.g., via email or shared folder) into opening it in Simcenter Femap. The vulnerable file parsing code processes the malformed file and either crashes the application or executes arbitrary code with the user's access level.
Prerequisites
  • User interaction required: victim must open a malicious BMP file in Simcenter Femap
  • Affected version of Simcenter Femap (< V2606.0001) must be installed on the system
local file parsing vulnerabilityuser interaction requiredaffects engineering workstationscode execution possiblehigh CVSS score (7.8)
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (1)
ProductAffected VersionsFix Status
Simcenter Femap < V2606.0001< 2606.00012606.0001
Remediation & Mitigation
0/3
Do now
0/1
HARDENINGEducate users not to open BMP files from untrusted sources, especially unsolicited attachments or files from external parties
Schedule — requires maintenance window
0/2

Patching may require device reboot — plan for process interruption

HOTFIXUpdate Simcenter Femap to version 2606.0001 or later
WORKAROUNDConsider implementing file type restrictions or disabling BMP file imports if not required for engineering workflows
API: /api/v1/advisories/d14b1310-f51f-4eba-935f-f2721ace6002

Get OT security insights every Tuesday

Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.