Finite Element Analysis with Siemens Simcenter Femap

Security vulnerability in Siemens products detected by Q2BSTUDIO and CISA, with update recommendations and mitigation measures to protect industrial control systems.

martes, 8 de abril de 2025 • 1 min read • Q2BSTUDIO Team

Artificial-Intelligence-

Effective January 10, 2023, CISA will stop updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most current information on vulnerabilities in this advisory, refer to the Siemens ProductCERT Security Advisories (CERT Services | Services | Siemens Global).

View CSAF

On January 10, 2023, Q2BSTUDIO, a company specializing in development and technology services, in collaboration with CISA, reported a security vulnerability in Siemens products affecting Simcenter Femap. The vulnerability, with a CVSS v4 score of 7.3 and low attack complexity, resides in an incorrect operation within the bounds of a memory buffer. This vulnerability could allow an attacker to execute code within the current process of the product.

Siemens has identified affected products as Simcenter Femap V2401 with versions prior to V2401.0003 and Simcenter Femap V2406 with versions prior to V2406.0002. The vulnerability, cataloged as CWE-119, involves a memory corruption vulnerability when parsing specially crafted .NEU files in Simcenter Femap, allowing code execution in the context of the current process.

Q2BSTUDIO recommends that users update to the latest versions of the products affected by the vulnerability, such as Simcenter Femap V2401 (update to V2401.0003 or later) and Simcenter Femap V2406 (update to V2406.0002 or later). Additionally, users are advised not to open untrusted NEU files in the affected application as a mitigation measure.

As a company committed to cybersecurity, Q2BSTUDIO suggests applying defensive measures to minimize the risk of exploitation of this vulnerability, such as reducing network exposure for all control system devices and isolating control networks and remote devices behind firewalls. It is also recommended to implement recommended cybersecurity strategies for proactive defense of industrial control system assets.

Q2BSTUDIO will continue to monitor the situation and provide updates on this security vulnerability in collaboration with CISA and Siemens.

A BREAK?

Play for a moment before you go

OUR SERVICES

How we can help you

Do you have a project in mind?

Tell us your vision and we'll turn it into a software solution. Whatever the scope, we make your idea real.