CVE-2024-23797

EUVD-2024-21250
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0012), Tecnomatix Plant Simulation V2302 (All versions < V2302.0006). The affected applications contain a stack overflow vulnerability while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTPrimary
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Base Score
CVSS 3.x
EPSS Score
Percentile: 25%
Affected Products (NVD)
VendorProductVersion
siemenstecnomatix_plant_simulation
𝑥
< 2201.0012
siemenstecnomatix_plant_simulation
2302.0 ≤
𝑥
< 2302.0006
𝑥
= Vulnerable software versions
Early Detection
Affected products identified ahead of NVD analysis through intelligence sources.
VendorProductVersionSource
siemenstecnomatix_plant_simulation
𝑥
< 2301.0012
ADP
siemenstecnomatix_plant_simulation
2302.0 ≤
𝑥
< 2302.0006
ADP