Post

Siemens Parasolid Vulnerability Advisory

Siemens Parasolid Vulnerability Advisory

Siemens Parasolid Vulnerability Advisory 🚨

Published Date: August 13, 2026
Source: CISA

Parasolid is affected by an out-of-bounds read vulnerability that could be triggered when the application reads files in X_T format. This vulnerability could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends updating to the latest versions. This vulnerability impacts Critical Infrastructure Sectors, specifically Critical Manufacturing, and is deployed worldwide.

Affected Versions

The following versions of Siemens Parasolid are affected by CVE-2026-64629:

  • Parasolid V38.0 vers:<38.0.235
  • Parasolid V38.1 vers:<38.1.230

The affected applications contain an out-of-bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. The relevant CWE for this vulnerability is CWE-125 Out-of-bounds Read.

Remediation Steps

For remediation, Siemens recommends updating affected products. This includes updating to V38.0.235 or later for Parasolid V38.0, and updating to V38.1.230 or later for Parasolid V38.1. Siemens ProductCERT reported this vulnerability to CISA. The initial release date for this advisory was August 11, 2026.

Security Recommendations

As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens advises configuring the environment according to their operational guidelines for Industrial Security and following the recommendations in the product manuals. CISA also recommends users take defensive measures to minimize the exploitation risk of these vulnerabilities. Users should minimize network exposure for all control system devices and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing that VPNs may have vulnerabilities and should be updated to the most recent version available.

For more information, please refer to the full advisory: Read full article

This post is licensed under CC BY 4.0 by the author.