CISA

Siemens Simcenter Nastran

From Cybersecurity and Infrastructure Security Agency ↗

Simcenter Nastran is affected by a stack overflow vulnerability that could be triggered when an application binary reads arbitrary string as a file argument. If a user is tricked to run one of the impacted application binary with a malicious string, an attacker could leverage the vulnerability to perform remote code execution in the context of the current process. Siemens has released new versions for the affected products and recommends to update to the latest versions.

The following versions of Siemens Simcenter Nastran are affected:

Simcenter Femap vers:intdot/