First published: Tue Apr 09 2024(Updated: )
A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.9), Teamcenter Visualization V2312 (All versions < V2312.0004). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted X_T files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens JT2Go | <V2312.0004 | |
Parasolid | <V35.1.254 | |
Parasolid | <V36.0.207 | |
Parasolid | <V36.1.147 | |
Siemens Teamcenter Visualization | <V14.2.0.12 | |
Siemens Teamcenter Visualization | <V14.3.0.9 | |
Siemens Teamcenter Visualization | <V2312.0004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-26277 has been classified with a high severity due to its impact on multiple Siemens software products.
To fix CVE-2024-26277, update JT2Go to version V2312.0004 or later, Parasolid to versions V35.1.254, V36.0.207, V36.1.147 or later, and Teamcenter Visualization to version V14.2.0.12 or V14.3.0.9 or later.
CVE-2024-26277 affects Siemens JT2Go, Parasolid versions prior to V35.1.254, V36.0.207, V36.1.147, and Teamcenter Visualization versions prior to V14.2.0.12 and V14.3.0.9.
Yes, patches are available for all affected products; users should download and install the latest versions to mitigate the vulnerability.
CVE-2024-26277 can potentially allow unauthorized access or manipulation of data in the affected Siemens software applications.