CVE-2025-40764: Siemens Simcenter Femap
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been identified in Simcenter Femap V2406 (All versions < V2406.0003), Simcenter Femap V2412 (All versions < V2412.0002). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of the current process.
Affected products
- Siemens Simcenter Femap: from 2406.0000, before 2406.0003 (fixed in 2406.0003); from 2412.0000, before 2412.0002 (fixed in 2412.0002)
Published 2025-08-12. Last modified 2026-06-17.