Heap-Based Buffer Overflow Vulnerability Affects Simcenter Nastran
CVE-2024-41981
7.8HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 8 October 2024
Summary
A vulnerability has been identified in the Simcenter Femap software that allows for a heap-based buffer overflow when processing specially crafted BDF files. This flaw enables attackers to potentially execute arbitrary code within the context of the current process, which could lead to unauthorized access and manipulation of sensitive data. The affected versions include all variations of Simcenter Femap V2306, V2401, and V2406. Users of these versions are advised to assess their security posture and apply relevant mitigations.
Affected Version(s)
Simcenter Femap V2306 0
Simcenter Femap V2401 0
Simcenter Femap V2406 0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved