First published: Tue Feb 13 2024(Updated: )
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted SPP files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Tecnomatix Plant Simulation | >=2302.0<2302.0007 | |
Siemens Tecnomatix Plant Simulation | =2201.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-23801 has a severity rating that allows attackers to exploit the vulnerability for denial of service.
To fix CVE-2024-23801, users should update to Tecnomatix Plant Simulation version 2302.0007 or later, or conduct appropriate configurations for version 2201.
CVE-2024-23801 affects all versions of Tecnomatix Plant Simulation V2201 and versions of V2302 prior to 2302.0007.
CVE-2024-23801 is identified as a null pointer dereference vulnerability, particularly when parsing specially crafted SPP files.
Yes, an attacker could leverage CVE-2024-23801 to cause a denial of service through a specially crafted file.