Femap Vulnerability Could Allow Execution of Code in Context of Current Process
CVE-2024-24923

7.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
13 February 2024

Summary

An out of bounds read vulnerability exists in Simcenter Femap, impacting all versions before V2401.0000 and V2306.0001. This vulnerability arises during the parsing of specially crafted Catia MODEL files, potentially allowing an attacker to execute code within the context of the affected application. The flaw could lead to unauthorized access or manipulation of data, emphasizing the need for users to apply the latest security updates to their products to safeguard against possible exploitation.

Affected Version(s)

Simcenter Femap 0

Simcenter Femap 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.