{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/cve-2026-64629/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"cvss":7.8,"id":"CVE-2026-64629"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Parasolid"],"_cs_severities":["high"],"_cs_tags":["vulnerability","industrial-control-systems","ics","cve-2026-64629"],"_cs_type":"advisory","_cs_vendors":["Siemens"],"content_html":"\u003cp\u003eSiemens Parasolid is affected by an out-of-bounds read vulnerability, tracked as CVE-2026-64629, which occurs when the application parses specially crafted X_T (Parasolid Transmit) files. The vulnerability stems from improper boundary checking during the ingestion of these CAD data files. An attacker capable of delivering a malicious X_T file to a user or system running an affected version of Parasolid could trigger memory corruption, resulting in either a denial-of-service via application crash or potential arbitrary code execution within the security context of the host process. This vulnerability affects Parasolid version 38.0 (before 38.0.235) and version 38.1 (before 38.1.230). Given that Parasolid is widely used in CAD/CAM/CAE software across critical manufacturing sectors, organizations should prioritize patching to the latest vendor-supplied versions.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows for arbitrary code execution or service disruption within the context of the user running the CAD software. This vulnerability is particularly relevant to critical manufacturing environments where CAD/CAM tools are integrated into design and production workflows. Exploitation requires user interaction to open a malicious file, but the impact includes full compromise of the local application process.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eApply the security patches provided by Siemens immediately for all affected versions of Parasolid.\u003c/li\u003e\n\u003cli\u003eUpdate Parasolid V38.0 installations to V38.0.235 or later.\u003c/li\u003e\n\u003cli\u003eUpdate Parasolid V38.1 installations to V38.1.230 or later.\u003c/li\u003e\n\u003cli\u003eUtilize the Siemens operational guidelines for Industrial Security to segment CAD workstations from critical control networks and minimize the attack surface of systems running Parsolid-based applications.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-13T16:51:35Z","date_published":"2026-08-13T16:51:35Z","id":"https://feed.craftedsignal.io/briefs/2026-08-siemens-parasolid/","summary":"Siemens Parasolid contains an out-of-bounds read vulnerability (CVE-2026-64629) in its X_T file parsing logic that can lead to arbitrary code execution or application crashes.","title":"Out-of-Bounds Read Vulnerability in Siemens Parasolid","url":"https://feed.craftedsignal.io/briefs/2026-08-siemens-parasolid/"}],"language":"en","title":"CraftedSignal Threat Feed - Cve-2026-64629","version":"https://jsonfeed.org/version/1.1"}