CVE-2023-24978: High severity siemens tecnomatix plant simulation vulnerability
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted SPP files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-19788)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-24978?
CVE-2023-24978 is considered a medium severity vulnerability due to the potential for code execution.
How do I fix CVE-2023-24978?
To fix CVE-2023-24978, upgrade to Siemens Tecnomatix Plant Simulation version 2201.0006 or later.
What versions of Tecnomatix Plant Simulation are affected by CVE-2023-24978?
CVE-2023-24978 affects all versions of Tecnomatix Plant Simulation prior to version 2201.0006.
What type of attack can exploit CVE-2023-24978?
An attacker can exploit CVE-2023-24978 by crafting a specially designed SPP file that leads to uninitialized pointer access.
Is user intervention required for the exploitation of CVE-2023-24978?
Yes, user intervention is required as the exploit occurs when the specially crafted SPP file is processed by the application.