La superficie esposta non è l’installazione di Solid Edge in sé, ma il flusso di lavoro che apre file PAR, PSM e DFT: un documento CAD costruito ad arte può portare il parser a eseguire codice nel processo corrente. Per chi scambia progetti con fornitori, clienti o reparti interni, il rischio nasce nel gesto normale di aprire un file apparentemente legittimo.
Siemens ha corretto il problema con SE2025 Update 15 e SE2026 Update 7, che chiudono sette CVE distinte. Le falle riguardano il parsing di file DFT e, secondo CISA, possono causare crash o code execution; non serve un exploit sofisticato sul sistema, basta far leggere al programma un file preparato male. Questo rende i workstation di progettazione un punto d’ingresso concreto ogni volta che il flusso accetta input non fidati.
Siemens Simcenter Nastran Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument.
Siemens Solid Edge Summary Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format.