First published: Tue Apr 09 2024(Updated: )
A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.9), Teamcenter Visualization V2312 (All versions < V2312.0004). The affected application contains a stack exhaustion vulnerability while parsing a specially crafted X_T file. This could allow an attacker to cause denial of service condition.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens JT2Go | <V2312.0004 | |
Parasolid | <V35.1.254<V36.0.207<V36.1.147 | |
Siemens Teamcenter Visualization | <V14.2.0.12<V14.3.0.9<V2312.0004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-26276 has been classified with a high severity level due to the potential risk it poses to affected products.
To mitigate CVE-2024-26276, upgrade to the latest versions of the affected software listed in the vulnerability description.
CVE-2024-26276 impacts JT2Go versions below V2312.0004, Parasolid versions below V35.1.254, V36.0.207, V36.1.147, and Teamcenter Visualization versions below V14.2.0.12 and V14.3.0.9.
CVE-2024-26276 affects Siemens JT2Go, Parasolid, and Teamcenter Visualization products.
Currently, the recommended approach is to upgrade the affected software, as no official workaround has been provided.