CNNVD-202510-2036 Information

CNNVD ID

CNNVD-202510-2036

CVE-2025-40809

  • CNNVD Published: 2025-10-14

Description (Chinese)

Siemens Solid Edge SE2025和Siemens Solid Edge SE2024都是德国西门子(Siemens)公司的一款开发软件。 Siemens Solid Edge SE2025和Siemens Solid Edge SE2024存在缓冲区错误漏洞,该漏洞源于解析特制PRT文件时存在越界写入,可能导致应用程序崩溃或执行任意代码。以下版本受到影响:Siemens Solid Edge SE2024 V224.0 Update 14之前版本和Siemens Solid Edge SE2025 V225.0 Update 6之前版本。

Description (English)

Siemens Solid Edge SE2025 and Siemens Solid Edge SE2024 are both development software for Siemens, Germany. Siemens Solid Edge SE2025 and Siemens Solid Edge SE2024 have an error loophole in the buffer zone, which arises from cross-border writing in the analysis of specially created PRT files, which could lead to a breakdown of the application or the implementation of any code. The following versions have been affected: Siemens Solid Edge SE2024 V224.0 Update 14 and Siemens Solid Edge SE2025 V225.0 Update 6.

Hazard Level

Medium

Vulnerability Type

缓冲区错误

Affected Vendor

西门子

Published

2025-10-14

Last Modified

2026-02-24

References

https://cert-portal.siemens.com/productcert/html/ssa-541582.html

Patch

https://www.siemens.com/global/en/products/services/cert.html#SiemensSecurityAdvisories

Share on: