Our takeSiemens fixed multiple file-parsing flaws in Solid Edge that let specially crafted PAR, PSM or DFT files crash the app or run code. Update to the latest version.Cyber Resilience desk
Sources (1)
- cisa_ics · cisa_ics
What this means for you — Security leader:Update Siemens Solid Edge to the latest version if you use it; the vulnerabilities allow crashes or arbitrary code execution via malformed PAR, PSM, or DFT files.
What this means for you — Lean IT orgs:If you use Siemens Solid Edge, update it to the newest version right away. Most teams without this software can ignore the advisory.
What this means for you — MSP:Audit client environments for Siemens Solid Edge usage and push the vendor-recommended updates; the file-parsing flaws can lead to code execution on affected workstations.
What this means for you — Researcher:Review the Siemens CSAF and CISA advisory for the exact affected Solid Edge versions and the PAR/PSM/DFT parsing flaws.