Severity
High
Analysis Summary
CVE-2025-40936 CVSS:7.8
A vulnerability has been identified in PS/IGES Parasolid Translator Component. The affected applications contains an out of bounds read vulnerability while parsing specially crafted IGS files. This could allow an attacker to crash the application or execute code in the context of the current process.
CVE-2025-40834 CVSS:6.8
A vulnerability has been identified in Mendix RichText. Affected widget does not properly neutralize the input. This could allow an attacker to execute cross-site scripting attacks.
Impact
- Gain Access
- Cross-Site Scripting
Indicators of Compromise
CVE
CVE-2025-40936
CVE-2025-40834
Affected Vendors
Siemens
Affected Products
- Siemens PS/IGES Parasolid Translator Component V29.0.258
- Siemens Mendix RichText V4.0.0 - V4.6.1
Remediation
Refer to Siemens Security Advisory for patch, upgrade, or suggested workaround information.