Our takeSiemens patched file-parsing flaws in Solid Edge (PAR, PSM, DFT formats) that could crash the app or let an attacker execute arbitrary code via a crafted file. Update to the latest version if you use Solid Edge for CAD design.Cyber Resilience desk
Sources (1)
- cisa_advisories · cisa_advisories
What this means for you — Security leader:Update to the latest Solid Edge release if you run it in your environment; the vulnerabilities allow arbitrary code execution via crafted PAR, PSM, or DFT files.
What this means for you — Lean IT orgs:If your team uses Siemens Solid Edge, install the newest version as soon as possible. Most offices without this CAD software can ignore the update.
What this means for you — MSP:Check client environments for Siemens Solid Edge and push the vendor's latest release; the parsing flaws let specially crafted files execute code.
What this means for you — Researcher:Review the Siemens advisory and CSAF for the full list of affected Solid Edge versions and fixed CVEs.