Stack Overflow Vulnerability in Tecnomatix Plant Simulation Could Allow Code Execution
CVE-2024-23798

7.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
13 February 2024

Summary

A stack overflow vulnerability has been identified in Siemens' Tecnomatix Plant Simulation, specifically in versions V2201 (all versions prior to V2201.0012) and V2302 (all versions prior to V2302.0006). This security issue is triggered while parsing carefully crafted WRL files, which may lead to unauthorized code execution within the context of the running process. As users operate with these affected applications, attackers could exploit this vulnerability to gain control over system processes, heightening the importance of applying available security updates or patches.

Affected Version(s)

Tecnomatix Plant Simulation V2201 0

Tecnomatix Plant Simulation V2302 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.