📧 info@ciso.sa | 📱 +966550939344 | Riyadh, Kingdom of Saudi Arabia
🔧 Scheduled Maintenance — Saturday 2:00-4:00 AM AST. Some features may be temporarily unavailable.    ●   
💎
Pro Plan 50% Off Unlock all AI features, unlimited reports, and priority support. Upgrade
Search Center
ESC to close
Global apt Government/Critical Infrastructure CRITICAL 1h Global vulnerability Enterprise Software / Data Analytics CRITICAL 2h Global vulnerability Artificial Intelligence and Technology HIGH 5h Global general Technology and Artificial Intelligence MEDIUM 8h Global general Technology and Artificial Intelligence HIGH 9h Global vulnerability Higher Education CRITICAL 19h Global data_breach Government HIGH 20h Global supply_chain Software Development and Open Source Communities CRITICAL 20h Global malware Software Development CRITICAL 20h Global phishing Multiple Sectors HIGH 20h Global apt Government/Critical Infrastructure CRITICAL 1h Global vulnerability Enterprise Software / Data Analytics CRITICAL 2h Global vulnerability Artificial Intelligence and Technology HIGH 5h Global general Technology and Artificial Intelligence MEDIUM 8h Global general Technology and Artificial Intelligence HIGH 9h Global vulnerability Higher Education CRITICAL 19h Global data_breach Government HIGH 20h Global supply_chain Software Development and Open Source Communities CRITICAL 20h Global malware Software Development CRITICAL 20h Global phishing Multiple Sectors HIGH 20h Global apt Government/Critical Infrastructure CRITICAL 1h Global vulnerability Enterprise Software / Data Analytics CRITICAL 2h Global vulnerability Artificial Intelligence and Technology HIGH 5h Global general Technology and Artificial Intelligence MEDIUM 8h Global general Technology and Artificial Intelligence HIGH 9h Global vulnerability Higher Education CRITICAL 19h Global data_breach Government HIGH 20h Global supply_chain Software Development and Open Source Communities CRITICAL 20h Global malware Software Development CRITICAL 20h Global phishing Multiple Sectors HIGH 20h
Vulnerabilities

CVE-2026-22923

High
A vulnerability has been identified in NX (All versions < V2512). The affected application contains a data validation vulnerability that could allow an attacker with local access to interfere with int
CWE-121 — Weakness Type
Published: Feb 10, 2026  ·  Modified: Feb 28, 2026  ·  Source: NVD
CVSS v3
7.8
🔗 NVD Official
📄 Description (English)

A vulnerability has been identified in NX (All versions < V2512). The affected application contains a data validation vulnerability that could allow an attacker with local access to interfere with internal data during the PDF export process that could potentially lead to arbitrary code execution.

🤖 AI Executive Summary

A critical data validation vulnerability in Siemens NX versions prior to V2512 allows local attackers to manipulate internal data during PDF export operations, potentially leading to arbitrary code execution. This vulnerability affects engineering and design workflows across multiple sectors in Saudi Arabia. Immediate patching to version V2512 or later is strongly recommended given the high CVSS score of 7.8 and the prevalence of NX in critical infrastructure design.

📄 Description (Arabic)

🤖 AI Intelligence Analysis Analyzed: Apr 29, 2026 00:25
🇸🇦 Saudi Arabia Impact Assessment
This vulnerability poses significant risk to Saudi organizations in energy sector (ARAMCO, Saudi Aramco subsidiaries), aerospace and defense contractors, government engineering departments (Ministry of Defense, General Authority for Military Industries), and manufacturing facilities. NX is widely used in CAD/CAM operations for critical infrastructure design. Local access requirement limits immediate risk but insider threats and compromised workstations present realistic attack vectors in these sectors. Potential impact includes unauthorized modification of engineering designs, intellectual property theft, and supply chain compromise.
🏢 Affected Saudi Sectors
Energy (ARAMCO, Saudi Aramco, oil & gas) Aerospace and Defense Government (Ministry of Defense, GAMI) Manufacturing and Industrial Engineering and Construction Telecommunications Infrastructure
⚖️ Saudi Risk Score (AI)
7.8
/ 10.0
🔧 Remediation Steps (English)
IMMEDIATE ACTIONS:
1. Identify all NX installations across the organization using asset management tools
2. Prioritize systems in engineering departments, design centers, and manufacturing facilities
3. Restrict local access to NX workstations to authorized personnel only
4. Implement access controls and monitor local user accounts
5. Review recent PDF export activities for suspicious modifications

PATCHING GUIDANCE:
1. Upgrade all NX installations to version V2512 or later immediately
2. Test patches in non-production environment first
3. Create backup of NX configuration and project files before patching
4. Verify patch installation using Siemens verification tools
5. Schedule patching during maintenance windows to minimize operational disruption

COMPENSATING CONTROLS (if immediate patching not possible):
1. Disable PDF export functionality if not critical to operations
2. Implement application whitelisting on NX workstations
3. Use file integrity monitoring on NX project directories
4. Restrict NX execution to specific user accounts with minimal privileges
5. Monitor process execution for suspicious PDF-related activities

DETECTION RULES:
1. Monitor for unexpected PDF export processes from NX
2. Alert on PDF files with suspicious embedded objects or scripts
3. Track modifications to NX project files immediately after PDF export
4. Monitor for code execution attempts originating from PDF processing
5. Log all local access attempts to NX workstations
🔧 خطوات المعالجة (العربية)
الإجراءات الفورية:
1. تحديد جميع تثبيتات NX عبر المنظمة باستخدام أدوات إدارة الأصول
2. إعطاء الأولوية للأنظمة في أقسام الهندسة ومراكز التصميم والمنشآت الإنتاجية
3. تقييد الوصول المحلي إلى محطات عمل NX للموظفين المصرح لهم فقط
4. تنفيذ عناصر التحكم في الوصول ومراقبة حسابات المستخدمين المحليين
5. مراجعة أنشطة تصدير PDF الأخيرة للتعديلات المريبة

إرشادات التصحيح:
1. ترقية جميع تثبيتات NX إلى الإصدار V2512 أو أحدث فوراً
2. اختبار التصحيحات في بيئة غير الإنتاج أولاً
3. إنشاء نسخة احتياطية من إعدادات NX وملفات المشروع قبل التصحيح
4. التحقق من تثبيت التصحيح باستخدام أدوات التحقق من Siemens
5. جدولة التصحيح خلال نوافذ الصيانة لتقليل تعطل العمليات

عناصر التحكم البديلة (إذا لم يكن التصحيح الفوري ممكناً):
1. تعطيل وظيفة تصدير PDF إذا لم تكن حرجة للعمليات
2. تنفيذ قائمة بيضاء للتطبيقات على محطات عمل NX
3. استخدام مراقبة سلامة الملفات على دلائل مشاريع NX
4. تقييد تنفيذ NX لحسابات مستخدمين محددة بامتيازات دنيا
5. مراقبة تنفيذ العمليات للأنشطة المريبة المتعلقة بـ PDF

قواعد الكشف:
1. مراقبة عمليات تصدير PDF غير المتوقعة من NX
2. التنبيه على ملفات PDF التي تحتوي على كائنات أو برامج نصية مريبة مضمنة
3. تتبع التعديلات على ملفات مشاريع NX فوراً بعد تصدير PDF
4. مراقبة محاولات تنفيذ الأكواد الناشئة من معالجة PDF
5. تسجيل جميع محاولات الوصول المحلي إلى محطات عمل NX
📋 Regulatory Compliance Mapping
🟢 NCA ECC 2024
ECC 2024 A.5.1.1 - Access Control Policies ECC 2024 A.6.1.1 - Asset Management ECC 2024 A.8.1.1 - Vulnerability Management ECC 2024 A.12.6.1 - Management of Technical Vulnerabilities
🔵 SAMA CSF
SAMA CSF ID.RA-1 - Asset Management and Inventory SAMA CSF PR.IP-12 - Software Development and Quality Assurance SAMA CSF DE.CM-1 - Detection and Analysis SAMA CSF RS.MI-2 - Incident Response and Recovery
🟡 ISO 27001:2022
ISO 27001:2022 A.5.23 - Information Security for Supplier Relationships ISO 27001:2022 A.8.1 - User Endpoint Devices ISO 27001:2022 A.8.2 - Privileged Access Rights ISO 27001:2022 A.8.6 - Access Control for Change Management
📦 Affected Products / CPE 1 entries
siemens:nx
📊 CVSS Score
7.8
/ 10.0 — High
📊 CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Attack VectorL — Low / Local
Attack ComplexityL — Low / Local
Privileges RequiredN — None / Network
User InteractionR — Required
ScopeU — Unchanged
ConfidentialityH — High
IntegrityH — High
AvailabilityH — High
📋 Quick Facts
Severity High
CVSS Score7.8
CWECWE-121
EPSS0.01%
Exploit No
Patch ✓ Yes
Published 2026-02-10
Source Feed nvd
Views 2
🇸🇦 Saudi Risk Score
7.8
/ 10.0 — Saudi Risk
Priority: HIGH
🏷️ Tags
CWE-121
Share this CVE

💬 Comments

0
Loading comments
📣 Found this valuable?
Share it with your cybersecurity network
in LinkedIn 𝕏 X / Twitter 💬 WhatsApp ✈ Telegram
🍪 Privacy Preferences
CISO Consulting — Compliant with Saudi Personal Data Protection Law (PDPL)
We use cookies and similar technologies to provide the best experience on our platform. You can choose which types you accept.
🔒
Essential Always On
Required for the website to function properly. Cannot be disabled.
📋 Sessions, CSRF tokens, authentication, language preferences
📊
Analytics
Help us understand how visitors use the site and improve performance.
📋 Page views, session duration, traffic sources, performance metrics
⚙️
Functional
Enable enhanced features like content personalization and preferences.
📋 Dark/light theme, font size, custom dashboards, saved filters
📣
Marketing
Used to deliver content and ads relevant to your interests.
📋 Campaign tracking, retargeting, social media analytics
Privacy Policy →
CISO AI Assistant
Ask anything · Documents · Support
🔐

Introduce Yourself

Enter your details to access the full assistant

Your info is private and never shared
💬
CyberAssist
Online · responds in seconds
5 / 5
🔐 Verify Your Identity

Enter your email to receive a verification code before submitting a support request.

Enter to send · / for commands 0 / 2000
CISO AI · Powered by Anthropic Claude
✦ Quick Survey Help Us Improve CISO Consulting Your feedback shapes the future of our platform — takes less than 2 minutes.
⚠ Please answer this question to continue

How would you rate your overall experience with our platform?

Rate from 1 (poor) to 5 (excellent)

🎉
Thank you!
Your response has been recorded.