First published: Tue Feb 14 2023(Updated: )
A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2). The affected application contains a memory corruption vulnerability while parsing specially crafted DWG files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19069)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Solid Edge Se2023 | <2210.0002.004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24564 is a memory corruption vulnerability in Solid Edge SE2022 and SE2023.
CVE-2023-24564 affects all versions of Solid Edge SE2022 and SE2023 prior to V222.0MP12 or V223.0Update2, respectively.
The severity of CVE-2023-24564 is high with a CVSS score of 7.8.
To fix CVE-2023-24564, it is recommended to update Solid Edge to version V222.0MP12 or V223.0Update2 or later.
You can find more information about CVE-2023-24564 in the Siemens ProductCERT advisory at https://cert-portal.siemens.com/productcert/pdf/ssa-491245.pdf.