Buffer Overflow Vulnerability in Parasolid Could Allow Execution of Code
CVE-2024-31980

7.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 May 2024

Summary

An out of bounds write vulnerability has been identified in Parasolid, a widely used software for 3D solid modeling. This vulnerability arises while processing a specially crafted X_T part file, potentially allowing attackers to write beyond the allocated buffer length. If successfully exploited, it may enable attackers to execute arbitrary code within the context of the affected application, leading to unauthorized actions and data breaches. Users of Parasolid are strongly advised to update to the latest versions to safeguard against these security risks.

Affected Version(s)

Parasolid V35.1 0

Parasolid V36.0 0

Parasolid V36.1 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.