Skip to content
Threat Feed
high advisory

Out-of-Bounds Read Vulnerability in Siemens Parasolid

Siemens Parasolid contains an out-of-bounds read vulnerability (CVE-2026-64629) in its X_T file parsing logic that can lead to arbitrary code execution or application crashes.

CVE search metadata

CVE search record: CVE-2026-64629. Severity: high. CVSS: 7.8. EPSS: 0.11%. KEV: no. Product: Parasolid. Brief: Out-of-Bounds Read Vulnerability in Siemens Parasolid. Brief link: https://feed.craftedsignal.io/briefs/2026-08-siemens-parasolid/

Siemens Parasolid is affected by an out-of-bounds read vulnerability, tracked as CVE-2026-64629, which occurs when the application parses specially crafted X_T (Parasolid Transmit) files. The vulnerability stems from improper boundary checking during the ingestion of these CAD data files. An attacker capable of delivering a malicious X_T file to a user or system running an affected version of Parasolid could trigger memory corruption, resulting in either a denial-of-service via application crash or potential arbitrary code execution within the security context of the host process. This vulnerability affects Parasolid version 38.0 (before 38.0.235) and version 38.1 (before 38.1.230). Given that Parasolid is widely used in CAD/CAM/CAE software across critical manufacturing sectors, organizations should prioritize patching to the latest vendor-supplied versions.

Impact

Successful exploitation allows for arbitrary code execution or service disruption within the context of the user running the CAD software. This vulnerability is particularly relevant to critical manufacturing environments where CAD/CAM tools are integrated into design and production workflows. Exploitation requires user interaction to open a malicious file, but the impact includes full compromise of the local application process.

Recommendation

  • Apply the security patches provided by Siemens immediately for all affected versions of Parasolid.
  • Update Parasolid V38.0 installations to V38.0.235 or later.
  • Update Parasolid V38.1 installations to V38.1.230 or later.
  • Utilize the Siemens operational guidelines for Industrial Security to segment CAD workstations from critical control networks and minimize the attack surface of systems running Parsolid-based applications.

Immediate actions

Patch Parasolid V38.0 to V38.0.235 and V38.1 to V38.1.230

IT Operations 72h

Mitigations

Restrict file system permissions and implement application whitelisting for CAD-related file formats

immediate IT Operations

CVE-2026-64629