CNNVD-202510-2033 Information

CNNVD ID

CNNVD-202510-2033

CVE-2025-40812

  • CNNVD Published: 2025-10-14

Description (Chinese)

Siemens Solid Edge SE2025和Siemens Solid Edge SE2024都是德国西门子(Siemens)公司的一款开发软件。 Siemens Solid Edge SE2025和Siemens Solid Edge SE2024存在缓冲区错误漏洞,该漏洞源于解析特制PRT文件时存在越界读取,可能导致应用程序崩溃或在当前进程环境中执行代码。以下版本受到影响:Solid Edge SE2024 V224.0 Update 14之前版本和Solid Edge SE2025 V225.0 Update 6之前版本。

Description (English)

Siemens Solid Edge SE2025 and Siemens Solid Edge SE2024 are both development software for Siemens, Germany. Siemens Solid Edge SE2025 and Siemens Solid Edge SE2024 have a buffer zone error loophole, which stems from cross-border reading when deconstructing a specially created PRT file, which could lead to an application collapse or code implementation in the current process environment. The following versions were affected: Solid Edge SE 2024 V224.0 Update 14 and Solid Edge SE 2025 V225.0 Update 6.

Hazard Level

Medium

Vulnerability Type

缓冲区错误

Affected Vendor

西门子

Published

2025-10-14

Last Modified

2026-02-24

References

https://cert-portal.siemens.com/productcert/html/ssa-541582.html

Patch

https://www.siemens.com/global/en/products/services/cert.html#SiemensSecurityAdvisories

Share on: