Vulnerabilità · 41 giorni fa
La superficie esposta non è l’installazione di Solid Edge in sé, ma il flusso di lavoro che apre file PAR, PSM e DFT: un documento CAD costruito ad arte può portare il parser a eseguire codice nel processo corrente. Per chi scambia progetti con fornitori, clienti o reparti interni, il rischio nasce nel gesto normale di aprire un file apparentemente legittimo.
Siemens ha corretto il problema con SE2025 Update 15 e SE2026 Update 7, che chiudono sette CVE distinte. Le falle riguardano il parsing di file DFT e, secondo CISA, possono causare crash o code execution; non serve un exploit sofisticato sul sistema, basta far leggere al programma un file preparato male. Questo rende i workstation di progettazione un punto d’ingresso concreto ogni volta che il flusso accetta input non fidati.
CVE in questo aggiornamento
7 CVE
0 critiche · 7 alte · 0 medie · 0 basse
0 in CISA KEV · 0 con EPSS sopra 1%
Severità più alta: CVE-2026-50058 · 7.8 HIGH
EPSS più alto: CVE-2026-50058 · 0,16%
3 fonti che coprono questa storia
Siemens Simcenter Nastran | CISA
Siemens Simcenter Nastran Summary Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument.
Siemens Solid Edge Summary Solid Edge is affected by multiple file parsing vulnerabilities that could be triggered when the application reads specially crafted files in PAR, PSM or DFT format.
Siemens LOGO! Soft Comfort | CISA
Soft Comfort contains multiple vulnerabilities in its project-file encryption and password handling mechanisms.
Siemens RUGGEDCOM APE1808 | CISA
Siemens RUGGEDCOM APE1808 Summary Fortinet has published information on vulnerabilities in FortiOS.
Aggiornamenti per prodotti Siemens
Siemens ha rilasciato aggiornamenti di sicurezza per sanare molteplici vulnerabilità nei propri prodotti, di cui 1 con gravità “critica” e 13 con gravità “alta”.
Kwetsbaarheden verholpen in Siemens producten
Siemens heeft kwetsbaarheden verholpen in diverse producten als Desigo, Parasolid, RUGGEDCOM, SIMATIC, Siveillance en Solid Edge.
Part of the PlainSec briefing for 2026-08-14