CVE-2024-26276: Medium severity siemens jt2go vulnerability
A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.9), Teamcenter Visualization V2312 (All versions < V2312.0004). The affected application contains a stack exhaustion vulnerability while parsing a specially crafted XT file. This could allow an attacker to cause denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26276?
CVE-2024-26276 has been classified with a high severity level due to the potential risk it poses to affected products.
How do I fix CVE-2024-26276?
To mitigate CVE-2024-26276, upgrade to the latest versions of the affected software listed in the vulnerability description.
Which versions are affected by CVE-2024-26276?
CVE-2024-26276 impacts JT2Go versions below V2312.0004, Parasolid versions below V35.1.254, V36.0.207, V36.1.147, and Teamcenter Visualization versions below V14.2.0.12 and V14.3.0.9.
What software products are impacted by CVE-2024-26276?
CVE-2024-26276 affects Siemens JT2Go, Parasolid, and Teamcenter Visualization products.
Is there a workaround for CVE-2024-26276?
Currently, the recommended approach is to upgrade the affected software, as no official workaround has been provided.