Siemens Simcenter Nastran
Plan PatchCVSS 7.8ICS-CERT ICSA-26-230-02Aug 11, 2026
Siemens
Attack path
Attack VectorLocal
Auth RequiredNone
ComplexityLow
User InteractionRequired
Summary
Simcenter Nastran versions before V2606 contain a stack overflow vulnerability in file argument handling. When a user runs the application with a malicious string as a file argument, a stack overflow occurs that could allow arbitrary code execution in the context of the process.
What this means
What could happen
An attacker could execute arbitrary code on an engineering workstation running Simcenter Nastran if a user is tricked into opening a malicious file, potentially compromising design data and simulation results used for equipment validation.
Who's at risk
Engineering teams and design departments using Simcenter Nastran for finite element analysis and simulation, particularly those using the application on shared workstations or in environments where users receive external files.
How it could be exploited
An attacker sends a malicious file to an engineer. When the engineer opens the file with Simcenter Nastran, a stack overflow in the string parsing code triggers, allowing the attacker to execute arbitrary code in the context of the application running on the workstation.
Prerequisites
- User interaction required - engineer must open a malicious file
- Simcenter Nastran application installed and in use on the workstation
Low complexity attackUser interaction requiredCould compromise design integrity
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (2)
2 with fix
Remediation & Mitigation
0/1
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
HOTFIXUpdate Simcenter Nastran to version 2606 or later
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/380079a0-eb8c-4894-ad94-af9ff50c33dfGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.