Specially Crafted WRL File Vulnerability Affects Tecnomatix Plant Simulation
CVE-2024-45470
7.8HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 8 October 2024
Summary
An out of bounds write vulnerability has been detected in Siemens' Teamcenter Visualization and Tecnomatix Plant Simulation products, specifically when they process specially crafted WRL files. This flaw could permit an adversary to execute arbitrary code within the context of the application process. Users running versions of Teamcenter Visualization below 14.2.0.14 or 14.3.0.12, along with affected versions of Tecnomatix Plant Simulation, face significant risk if proper mitigations are not implemented promptly. Immediate patching is essential to protect against potential exploits.
Affected Version(s)
Teamcenter Visualization V14.2 0
Teamcenter Visualization V14.3 0
Teamcenter Visualization V2312 0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved