First published: Tue Feb 13 2024(Updated: )
A vulnerability has been identified in Simcenter Femap (All versions < V2401.0000). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted Catia MODEL file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21715)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simcenter Femap | <2401.0000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-24922 has been rated with a high severity due to its potential to allow code execution through an out of bounds write.
To mitigate CVE-2024-24922, update to a patched version of Simcenter Femap that is greater than V2401.0000.
CVE-2024-24922 allows attackers to execute arbitrary code by exploiting an out of bounds write when processing malicious Catia MODEL files.
All versions of Simcenter Femap prior to V2401.0000 are affected by CVE-2024-24922.
Yes, exploitation of CVE-2024-24922 can potentially lead to a complete system compromise through arbitrary code execution.