Specially Crafted MODEL Files Can Trigger Code Execution Vulnerability in Tecnomatix Plant Simulation
CVE-2024-35303
Key Information:
- Vendor
Siemens
- Vendor
- CVE Published:
- 11 June 2024
What is CVE-2024-35303?
A type confusion vulnerability has been discovered in Siemens Tecnomatix Plant Simulation software, particularly impacting versions prior to V2302.0012 for V2302 and prior to V2404.0001 for V2404. This vulnerability arises during the parsing of specially crafted MODEL files, potentially permitting an attacker to execute arbitrary code in the context of the current process. Proper mitigation strategies should be enforced to safeguard against unauthorized access and code execution risks inherent in this vulnerability.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Tecnomatix Plant Simulation V2302 0
Tecnomatix Plant Simulation V2404 0
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved