Siemens Solid Edge
Plan PatchCVSS 7.8ICS-CERT ICSA-26-225-12Aug 11, 2026
Siemens
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
Solid Edge contains multiple file parsing vulnerabilities in PAR, PSM, and DFT file formats. When the application reads a specially crafted file in one of these formats, a buffer overflow (CWE-125, CWE-787) or use-after-free (CWE-416) flaw can be triggered, allowing an attacker to crash the application or execute arbitrary code. Affected versions are Solid Edge SE2025 before version 225.0 Update 15 and Solid Edge SE2026 before version 226.0 Update 7.
What this means
What could happen
An attacker could crash Solid Edge or execute arbitrary code on a workstation by sending a specially crafted PAR, PSM, or DFT file to an engineer or designer. Since Solid Edge is used for product design and manufacturing, compromise could lead to loss of design data, system downtime, or lateral movement into your engineering network.
Who's at risk
This affects engineering and design workstations running Solid Edge SE2025 or SE2026. Your design teams, CAD engineers, and product development staff should be prioritized. Organizations with external supply chain collaboration or third-party design input are at higher risk.
How it could be exploited
An attacker crafts a malicious PAR, PSM, or DFT file and tricks an engineer into opening it in Solid Edge (via email, USB, or shared drive). When the file is parsed, a buffer overflow or use-after-free flaw is triggered, allowing code execution on the engineer's workstation with the privileges of the Solid Edge process.
Prerequisites
- User must open a malicious file in Solid Edge (social engineering or supply chain attack required)
- The malicious file must be in PAR, PSM, or DFT format (native Solid Edge formats)
Low complexity attackUser interaction required (file must be opened)Could affect engineering workstations and design dataAffects popular CAD software used in manufacturing and product design
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
Remediation & Mitigation
0/4
Do now
0/1HARDENINGTrain engineering staff to avoid opening design files from untrusted sources, especially via email or external media
Schedule — requires maintenance window
0/2Patching may require device reboot — plan for process interruption
HOTFIXUpdate Solid Edge SE2025 to version 225.0 Update 15 or later
HOTFIXUpdate Solid Edge SE2026 to version 226.0 Update 7 or later
Long-term hardening
0/1HARDENINGRestrict file sharing with external partners to a quarantine or secure review folder; require IT review before opening files in Solid Edge
CVEs (7)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/46f79681-3278-4399-b482-409adf40c1c8Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.