Specially Crafted WRL File Vulnerability Affects Tecnomatix Plant Simulation
CVE-2024-45470

7.8HIGH

Summary

An out of bounds write vulnerability has been detected in Siemens' Teamcenter Visualization and Tecnomatix Plant Simulation products, specifically when they process specially crafted WRL files. This flaw could permit an adversary to execute arbitrary code within the context of the application process. Users running versions of Teamcenter Visualization below 14.2.0.14 or 14.3.0.12, along with affected versions of Tecnomatix Plant Simulation, face significant risk if proper mitigations are not implemented promptly. Immediate patching is essential to protect against potential exploits.

Affected Version(s)

Teamcenter Visualization V14.2 0

Teamcenter Visualization V14.3 0

Teamcenter Visualization V2312 0

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.