Memory Corruption Vulnerability in Tecnomatix Plant Simulation
CVE-2024-45474
7.8HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 8 October 2024
Summary
A memory corruption vulnerability affects various versions of Siemens Teamcenter Visualization and Tecnomatix Plant Simulation products. The issue arises during the parsing of specially crafted WRL files, which could allow an attacker to execute arbitrary code within the context of the current process. This vulnerability can be exploited when combined with other weaknesses in the system, notably enhancing the potential impact on affected environments.
Affected Version(s)
Teamcenter Visualization V14.2 0
Teamcenter Visualization V14.3 0
Teamcenter Visualization V2312 0
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved