First published: Tue Oct 10 2023(Updated: )
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain a type confusion vulnerability while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21268)
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Tecnomatix | >=2201<2201.0009 | |
Siemens Tecnomatix | >=2302<2302.0003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-45204 is a vulnerability identified in Tecnomatix Plant Simulation V2201 and V2302, allowing for a type confusion vulnerability while parsing specially crafted IGS files.
All versions of Tecnomatix Plant Simulation V2201 before V2201.0009 and all versions of Tecnomatix Plant Simulation V2302 before V2302.0003 are affected by CVE-2023-45204.
The severity of CVE-2023-45204 is high with a CVSS score of 7.8.
An attacker can exploit CVE-2023-45204 by crafting malicious IGS files and tricking a user into opening or processing them.
Yes, a fix is available for CVE-2023-45204. It is recommended to update Tecnomatix Plant Simulation to version V2201.0009 or V2302.0003 to mitigate the vulnerability.