First published: Tue Feb 14 2023(Updated: )
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19810)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Tecnomatix Plant Simulation | <2201.0006 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24988 is a vulnerability identified in Tecnomatix Plant Simulation where the application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file, potentially allowing an attacker to execute code in the context of the application.
All versions of Tecnomatix Plant Simulation before V2201.0006 are affected by CVE-2023-24988.
CVE-2023-24988 has a severity rating of 7.8, which is considered high.
An attacker can exploit CVE-2023-24988 by providing a specially crafted SPP file, which triggers an out of bounds write and potentially allows the execution of arbitrary code.
Yes, the vulnerability has been fixed in version V2201.0006 of Tecnomatix Plant Simulation. It is recommended to update to this version or newer to mitigate the risk.