CVE-2026-64629
Received Received - Intake

Heap-based Buffer Overflow in Parasolid While Parsing X_T Files

Vulnerability report for CVE-2026-64629, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-11

Last updated on: 2026-08-11

Assigner: Siemens AG

Description

A vulnerability has been identified in Parasolid V38.0 (All versions < V38.0.235), Parasolid V38.1 (All versions < V38.1.230). The affected applications contains an out of bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-11
Last Modified
2026-08-11
Generated
2026-08-11
AI Q&A
2026-08-11
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
siemens parasolid to 38.0.235 (exc)
siemens parasolid to 38.1.230 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-125 The product reads data past the end, or before the beginning, of the intended buffer.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an out-of-bounds read issue in Parasolid software versions V38.0 and V38.1. It occurs when the application processes specially crafted X_T files, potentially allowing attackers to execute arbitrary code or crash the application by reading memory outside intended boundaries.

Detection Guidance

Detecting this vulnerability requires checking the installed version of Parasolid against the patched versions (V38.0.235 or later for V38.0 and V38.1.230 or later for V38.1). No specific commands are provided in the resources, but you can verify the version through the application's interface or configuration files.

Impact Analysis

If exploited, this vulnerability could let attackers run malicious code on your system, potentially leading to data theft, system damage, or unauthorized access. It requires user interaction, such as opening a maliciously crafted X_T file, to trigger.

Mitigation Strategies

Immediately update Parasolid to V38.0.235 or later for V38.0 and V38.1.230 or later for V38.1. Siemens also recommends protecting network access to devices and following operational security guidelines.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-64629. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart