Stack-Based Buffer Vulnerability in Solid Edge Products by Siemens
CVE-2023-24566
3.3LOW
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 14 February 2023
Summary
A stack-based buffer overflow vulnerability has been identified in Solid Edge versions prior to V222.0MP12 and V223.0Update2. This weakness arises from the application's inability to properly parse specially crafted PAR files, resulting in the possibility for an attacker to execute arbitrary code within the context of the affected process. Organizations using these versions of Solid Edge should implement immediate patches and review their security measures to mitigate potential exploitation.
Affected Version(s)
Solid Edge SE2022 All versions < V222.0MP12
Solid Edge SE2022 All versions
Solid Edge SE2023 All versions < V223.0Update2
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved