Tecnomatix Plant Simulation Vulnerability: Execution of Code in Context of Current Process Possible
CVE-2024-45466

7.8HIGH

Summary

An out-of-bounds read vulnerability exists in various versions of Siemens’ Teamcenter Visualization and Tecnomatix Plant Simulation applications. This flaw allows an attacker to read past the end of an allocated data structure while interpreting specially crafted WRL files. If exploited, this could lead to arbitrary code execution within the affected application’s process context. Users of all affected versions are urged to apply the necessary updates to mitigate potential risks.

Affected Version(s)

Teamcenter Visualization V14.2 0

Teamcenter Visualization V14.3 0

Teamcenter Visualization V2312 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.