CVE-2023-45204: Incorrect Type Cast
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain a type confusion vulnerability while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21268)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2023-45204?
CVE-2023-45204 is a vulnerability identified in Tecnomatix Plant Simulation V2201 and V2302, allowing for a type confusion vulnerability while parsing specially crafted IGS files.
What software versions are affected by CVE-2023-45204?
All versions of Tecnomatix Plant Simulation V2201 before V2201.0009 and all versions of Tecnomatix Plant Simulation V2302 before V2302.0003 are affected by CVE-2023-45204.
What is the severity of CVE-2023-45204?
The severity of CVE-2023-45204 is high with a CVSS score of 7.8.
How can an attacker exploit CVE-2023-45204?
An attacker can exploit CVE-2023-45204 by crafting malicious IGS files and tricking a user into opening or processing them.
Is there a fix available for CVE-2023-45204?
Yes, a fix is available for CVE-2023-45204. It is recommended to update Tecnomatix Plant Simulation to version V2201.0009 or V2302.0003 to mitigate the vulnerability.