Siemens Parasolid
View CSAF Summary Parasolid is affected by an out of bounds read vulnerability that could be triggered when the application reads files in X_T format. This could allow an attacker to crash the application or execute arbitrary code. Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Parasolid are affected: Parasolid V38.0 vers:intdot/<38.0.235 (CVE-2026-64629) Parasolid V38.1 vers:intdot/<38.1.230 (CVE-2026-64629) CVSS Vendor Equipment Vulnerabilities v3 7.8 Siemens Siemens Parasolid Out-of-bounds Read Background Critical Infrastructure Sectors: Critical Manufacturing Countries/Areas Deployed: Worldwide Company Headquarters Location: Germany Vulnerabilities Expand All + CVE-2026-64629 The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. View CVE Details Affected Products Siemens Parasolid Vendor: Siemens Product Version: Parasolid V38.0 < V38.0.235, Parasolid V38.1 < V38.1.230 Product Status: known_affected Remediations Vendor fix Update to V38.0.235 or later version https://support.sw.siemens.com/product/258316782/ Vendor fix Update to V38.1.230 or later version https://support.sw.siemens.com/product/258316782/ Relevant CWE: CWE-125 Out-of-bounds Read Metrics CVSS Version Base Score Base Severity Vector String 3.1 7.8 HIGH CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H Acknowledgments Siemens ProductCERT reported this vulnerability to CISA. General Recommendations As a general security measure, Siemens strongly recommends to protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens' operational guidelines for Industrial Security (Download: https://www.siemens.com/cert/operational-guidelines-industrial
CSIRTS triage
- What
- Out-of-bounds read vulnerability in X_T file parsing allows application crash or arbitrary code execution when reading specially crafted files.
- Who is affected
- Siemens Parasolid V38.0 and V38.1 users in critical manufacturing opening untrusted CAD files.
- Urgency
- Immediate; critical severity with CVSS 7.8 and potential code execution via file parsing.
- Action
- Update Parasolid V38.0 to 38.0.235 or later and V38.1 to 38.1.230 or later.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Parasolid
Get an email when a new Parasolid advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://www.cisa.gov/news-events/ics-advisories/icsa-26-225-10
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-646290.11% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 2% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-64629 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from CISA Cybersecurity Advisories
- criticalJohnson Controls Metasys2026-08-13
- criticalSiemens Siveillance Video2026-08-13
- criticalFlow Neuroscience FL-1002026-08-13
- criticalSiemens LOGO! Soft Comfort2026-08-13
- criticalJohnson Controls Inc. Airwall2026-08-13