First published: Tue Feb 14 2023(Updated: )
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted SPP file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19817)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Tecnomatix Plant Simulation | <2201.0006 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-24995 has been rated with a significant severity due to the potential for remote code execution.
To fix CVE-2023-24995, you should upgrade to Siemens Tecnomatix Plant Simulation version 2201.0006 or later.
CVE-2023-24995 can be exploited by an attacker through specially crafted SPP files that trigger an out of bounds write.
All versions of Tecnomatix Plant Simulation prior to version 2201.0006 are affected by CVE-2023-24995.
The impact of CVE-2023-24995 includes the potential for an attacker to execute arbitrary code in the context of the affected application.