CVE-2024-24925: High severity Siemens Simcenter Femap vulnerability
A vulnerability has been identified in Simcenter Femap (All versions < V2306.0000). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted Catia MODEL files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-22060)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Siemens Simcenter Femapto a version that resolves this vulnerability.Fixed in V2306.0000
Event History
Frequently Asked Questions
What is the severity of CVE-2024-24925?
CVE-2024-24925 is classified as a critical severity vulnerability due to the potential for remote code execution.
How do I fix CVE-2024-24925?
To fix CVE-2024-24925, you should update Simcenter Femap to version 2306.0000 or later.
What types of files are associated with CVE-2024-24925?
CVE-2024-24925 is specifically associated with parsing specially crafted Catia MODEL files.
What can an attacker achieve with CVE-2024-24925?
An attacker can exploit CVE-2024-24925 to execute arbitrary code in the context of the current process.
Which versions of Simcenter Femap are affected by CVE-2024-24925?
All versions of Simcenter Femap prior to 2306.0000 are affected by CVE-2024-24925.