{"id":"CVE-2025-40829","title":"A vulnerability has been identified in Simcenter Femap (All versions < V2512)","summary":"A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uninitialized memory vulnerability while parsing specially crafted SLDPRT files. This could allow an attacker to execute…","severity":"high","cvss":7.8,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","cwe":["CWE-908"],"vendor":"siemens","product":"simcenter_femap","affected":["simcenter_femap < 2512.0000"],"patched":["simcenter_femap 2512.0000"],"published":"2025-12-12","updated":"2026-10-07","sourceUpdated":"2026-10-07T20:10:01.970","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2025-40829","references":[{"url":"https://cert-portal.siemens.com/productcert/html/ssa-512988.html","label":"productcert@siemens.com"}],"tags":["nvd"],"epss":0.00198,"epssPercentile":0.08791,"ingestedAt":"2026-10-07T20:46:46.898Z","slug":"CVE-2025-40829","body":"## Overview\n\nA vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uninitialized memory vulnerability while parsing specially crafted SLDPRT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-27146)\n\n## Affected\n\n- `simcenter_femap < 2512.0000`\n\n## Remediation\n\nUpgrade past the affected range:\n\n- `simcenter_femap 2512.0000`","depth":"twilight","depthScore":43,"depthScoreParts":{"impact":42.9,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}