CVE-2024-1624: OS Command Injection vulnerability affecting documentation server on certain Releases of 3DEXPERIENCE, SIMULIA Abaqus, SIMULIA Isight and CATIA Composer
An OS Command Injection vulnerability affecting documentation server on 3DEXPERIENCE from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x, SIMULIA Abaqus from Release 2022 through Release 2024, SIMULIA Isight from Release 2022 through Release 2024 and CATIA Composer from Release R2023 through Release R2024. A specially crafted HTTP request can lead to arbitrary command execution.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-1624?
CVE-2024-1624 is classified as a high severity OS Command Injection vulnerability.
How do I fix CVE-2024-1624?
To fix CVE-2024-1624, it is recommended to update to the latest secure version of the affected software.
What products are affected by CVE-2024-1624?
CVE-2024-1624 affects Dassault Systèmes 3DEXPERIENCE, SIMULIA Abaqus, SIMULIA Isight, and CATIA Composer.
Which versions are vulnerable to CVE-2024-1624?
CVE-2024-1624 impacts versions from R2022x to R2024x for 3DEXPERIENCE and from 2022 to 2024 for SIMULIA Abaqus and Isight.
Is CVE-2024-1624 remotely exploitable?
Yes, CVE-2024-1624 can potentially be exploited remotely due to its command injection nature.