CVE-2023-44085: High severity siemens tecnomatix plant simulation vulnerability
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted SPP files. This could allow an attacker to execute code in the context of the current process.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-44085?
CVE-2023-44085 is a vulnerability that has been identified in Tecnomatix Plant Simulation V2201 and V2302. It allows for an out of bounds read past the end of an allocated structure while parsing specially crafted SPP files.
What is the severity of CVE-2023-44085?
CVE-2023-44085 has a severity rating of 7.8 (high).
Which versions of Tecnomatix Plant Simulation are affected by CVE-2023-44085?
All versions of Tecnomatix Plant Simulation V2201 (excluding V2201.0009) and V2302 (excluding V2302.0003) are affected by CVE-2023-44085.
What is the CWE category of CVE-2023-44085?
CVE-2023-44085 falls under the CWE category 125 (Out-of-bounds Read).
How can I fix CVE-2023-44085?
To fix CVE-2023-44085, users are advised to update Tecnomatix Plant Simulation to version V2201.0009 or V2302.0003 or apply the necessary patches provided by Siemens.