Heap-Based Buffer Overflow Vulnerability Affects Simcenter Nastran
CVE-2024-41981

7.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
8 October 2024

Summary

A vulnerability has been identified in the Simcenter Femap software that allows for a heap-based buffer overflow when processing specially crafted BDF files. This flaw enables attackers to potentially execute arbitrary code within the context of the current process, which could lead to unauthorized access and manipulation of sensitive data. The affected versions include all variations of Simcenter Femap V2306, V2401, and V2406. Users of these versions are advised to assess their security posture and apply relevant mitigations.

Affected Version(s)

Simcenter Femap V2306 0

Simcenter Femap V2401 0

Simcenter Femap V2406 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.