<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Cve-2026-64629 - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/cve-2026-64629/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 13 Aug 2026 16:51:35 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/cve-2026-64629/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Out-of-Bounds Read Vulnerability in Siemens Parasolid</title><link>https://feed.craftedsignal.io/briefs/2026-08-siemens-parasolid/</link><pubDate>Thu, 13 Aug 2026 16:51:35 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-08-siemens-parasolid/</guid><description>Siemens Parasolid contains an out-of-bounds read vulnerability (CVE-2026-64629) in its X_T file parsing logic that can lead to arbitrary code execution or application crashes.</description><content:encoded><![CDATA[<p>Siemens Parasolid is affected by an out-of-bounds read vulnerability, tracked as CVE-2026-64629, which occurs when the application parses specially crafted X_T (Parasolid Transmit) files. The vulnerability stems from improper boundary checking during the ingestion of these CAD data files. An attacker capable of delivering a malicious X_T file to a user or system running an affected version of Parasolid could trigger memory corruption, resulting in either a denial-of-service via application crash or potential arbitrary code execution within the security context of the host process. This vulnerability affects Parasolid version 38.0 (before 38.0.235) and version 38.1 (before 38.1.230). Given that Parasolid is widely used in CAD/CAM/CAE software across critical manufacturing sectors, organizations should prioritize patching to the latest vendor-supplied versions.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows for arbitrary code execution or service disruption within the context of the user running the CAD software. This vulnerability is particularly relevant to critical manufacturing environments where CAD/CAM tools are integrated into design and production workflows. Exploitation requires user interaction to open a malicious file, but the impact includes full compromise of the local application process.</p>
<h2 id="recommendation">Recommendation</h2>
<ul>
<li>Apply the security patches provided by Siemens immediately for all affected versions of Parasolid.</li>
<li>Update Parasolid V38.0 installations to V38.0.235 or later.</li>
<li>Update Parasolid V38.1 installations to V38.1.230 or later.</li>
<li>Utilize the Siemens operational guidelines for Industrial Security to segment CAD workstations from critical control networks and minimize the attack surface of systems running Parsolid-based applications.</li>
</ul>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>vulnerability</category><category>industrial-control-systems</category><category>ics</category><category>cve-2026-64629</category></item></channel></rss>