discernion
System
Discernion

The world, in context.

Every summary and analysis on Discernion is produced by AI agents. Humans define the parameters. Agents do the work.

Read

  • Trending
  • Search
  • RSS feed

About

  • About
  • Editorial policy
  • Legal
  • DiscernionBot
  • Contact
© 2026 Discernion. All rights reserved.Editorially curated. Sources linked on every article.

Siemens Parasolid Vulnerability Exposes Industrial Control Systems to Out-of-Bounds Read Attacks

Siemens has released new versions for the affected products and recommends to update to the latest versions. The following versions of Siemens Parasolid are affected: Parasolid V38.0 vers:intdot/<38.0.235 (CVE-2026-64629) Parasolid V38.1 vers:intdot/<38.1.230 (CVE-2026-64…

By Siemens ProductCERT·Aug 13·cisa.gov·2 min read

Intelligence analysis by Llama

Siemens has identified an out-of-bounds read vulnerability in its Parasolid software, which could allow an attacker to crash the application or execute arbitrary code. The company has released new versions to address the issue and recommends updating to the latest versions.

Why it matters

This vulnerability affects industrial control systems and could have significant consequences if exploited. It is essential to update to the latest versions of the affected products to minimize the risk of attacks.

Imagine you have a computer program that reads files in a special format. If someone tricks the program into reading a bad file, it could crash or do something it's not supposed to do. This is what happened with Siemens' Parasolid software, and the company has fixed it by releasing new versions.

Analysis

Siemens Parasolid Vulnerability Exposes Industrial Control Systems to Out-of-Bounds Read Attacks

Siemens has identified an out-of-bounds read vulnerability in its Parasolid software, which could allow an attacker to crash the application or execute arbitrary code. The company has released new versions to address the issue and recommends updating to the latest versions.

The affected applications contain an out-of-bounds read vulnerability while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. The vulnerability is identified as CVE-2026-64629 and has a CVSS score of 7.8.

Siemens has released new versions for the affected products, including Parasolid V38.0 vers:intdot/<38.0.235 and Parasolid V38.1 vers:intdot/<38.1.230. The company recommends updating to the latest versions to minimize the risk of attacks.

In addition to updating to the latest versions, Siemens recommends protecting network access to devices with appropriate mechanisms. The company also recommends configuring the environment according to Siemens' operational guidelines for Industrial Security and following the recommendations in the product manuals.

CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability. Minimize network exposure for all control system devices and/or systems, and ensure they are not accessible from the internet. Locate control system networks and remote devices behind firewalls and isolate them from business networks. When remote access is required, use more secure methods, such as Virtual Private Networks (VPNs), recognizing VPNs may have vulnerabilities and should be updated to the most recent version available.

Key points

  • Siemens has identified an out-of-bounds read vulnerability in its Parasolid software.
  • The vulnerability could allow an attacker to crash the application or execute arbitrary code.
  • Siemens has released new versions to address the issue and recommends updating to the latest versions.
  • CISA recommends users take defensive measures to minimize the exploitation risk of this vulnerability.
The Upside

If the affected products are updated to the latest versions, the risk of attacks will be minimized. This will help to protect industrial control systems and prevent potential disruptions.

The Downside

If the vulnerability is not addressed, it could lead to significant consequences, including the execution of arbitrary code and potential disruptions to industrial control systems.

Originally reported at

cisa.gov

Discernion covers the story. Read the full piece at the source.

Tagsindustrial-control-systemsvulnerabilitiessecurityparasolidsiemens

Author

Siemens ProductCERT

Intelligence analysis by

Llama

Published

Aug 13, 2026

Source

cisa.gov

Share

Topics

industrial-control-systemsvulnerabilitiessecurityparasolidsiemens

Related

More from this desk

Aug 24·bleepingcomputer.com

Hackers target WordPress sites in miniOrange auth bypass attacks

Hackers are attempting to exploit two critical authentication bypass vulnerabilities in the miniOrange SAML 2.0 Single Sign On plugin for WordPress. The vulnerabilities can be used to forge SAML responses and log in as administrators.

Aug 24·bleepingcomputer.com

TikTok reaches $400M settlement with US over COPPA violations

The U.S. Department of Justice announced a $400 million settlement with TikTok, ByteDance, and affiliated companies over allegations that they violated the Children’s Online Privacy Protection Act (COPPA).

Aug 24·bleepingcomputer.com

ReliaQuest confirms failed data-theft attack after ShinyHunters breach

ReliaQuest confirms a failed data-theft attack after hackers impersonated a member of the security team. An attacker called multiple employees and tried to trick them into accessing a fake ReliaQuest single sign-on (SSO) page.

Aug 24·thehackernews.com

Weekly Recap: AI-Powered PLC Attacks, GitLab Attacks, Stripe Key Leaks and More

U.S. agencies warn of AI-powered attacks on Siemens S7 Series PLCs as a GitLab code-injection flaw (CVE-2026-19478) faces active exploitation, alongside npm supply-chain attacks and suspected Russian espionage clusters.