Ansys maintains a specialized portfolio of computer-aided engineering and design software, including tools such as SpaceClaim and PyAnsys Geometry, that are embedded in product development and simulation workflows across manufacturing, aerospace, and industrial sectors. The vulnerability exposure concentrates in a small set of products and recurs through weakness classes characteristic of native computational codebases: out-of-bounds reads and writes, use-after-free conditions, uninitialized pointer access, and OS command injection, reflecting the memory-safety and input-handling demands of geometry processing and CAD operations. While the vendor's disclosure volume is modest relative to consumer or server-focused peers, the attack surface and downstream risk depend on deployment context—design tools exposed to untrusted CAD files or network input present higher risk than isolated workstations. Defenders should focus on inventory of Ansys products in engineering environments and prioritize patching where designs are imported from external or adversarial sources; current exploitation activity and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Ansys over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2022-40654HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerabili | Sep 15, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-40652HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerabili | Sep 15, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-40648HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerabili | Sep 15, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-40637HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerabili | Sep 15, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-40653HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerabili | Sep 15, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-40650HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerabili | Sep 15, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-40649HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerabili | Sep 15, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-40647HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerabili | Sep 15, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-40645HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerabili | Sep 15, 2022 | 7.8 | 25 | NO | NO |
CVE-2022-40644HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ansys SpaceClaim 2022 R1. User interaction is required to exploit this vulnerabili | Sep 15, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Ansys.
Media articles that mention a CVE ID that affects a product developed by Ansys — matched by CVE ID, not by vendor name.