CVE-2024-24924: High severity Siemens Simcenter Femap vulnerability
A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted Catia MODEL file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-22059)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Simcenter Femapto a version that resolves this vulnerability.Fixed in V2306.0000
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24924?
CVE-2024-24924 is considered a high-severity vulnerability due to its potential for code execution.
How do I fix CVE-2024-24924?
To fix CVE-2024-24924, upgrade to Siemens Simcenter Femap version 2306.0000 or later.
What types of attacks can exploit CVE-2024-24924?
CVE-2024-24924 can be exploited through specially crafted Catia MODEL files to execute arbitrary code.
Which versions of Simcenter Femap are affected by CVE-2024-24924?
All versions of Simcenter Femap prior to version 2306.0000 are affected by CVE-2024-24924.
Is there a patch available for CVE-2024-24924?
Yes, a patch is available in the form of an upgrade to Simcenter Femap version 2306.0000.