CVE-2024-26277: Null Pointer Dereference
A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.9), Teamcenter Visualization V2312 (All versions < V2312.0004). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted XT files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-26277?
CVE-2024-26277 has been classified with a high severity due to its impact on multiple Siemens software products.
How do I fix CVE-2024-26277?
To fix CVE-2024-26277, update JT2Go to version V2312.0004 or later, Parasolid to versions V35.1.254, V36.0.207, V36.1.147 or later, and Teamcenter Visualization to version V14.2.0.12 or V14.3.0.9 or later.
Which Siemens products are affected by CVE-2024-26277?
CVE-2024-26277 affects Siemens JT2Go, Parasolid versions prior to V35.1.254, V36.0.207, V36.1.147, and Teamcenter Visualization versions prior to V14.2.0.12 and V14.3.0.9.
Is there a patch available for CVE-2024-26277?
Yes, patches are available for all affected products; users should download and install the latest versions to mitigate the vulnerability.
What problems can CVE-2024-26277 cause?
CVE-2024-26277 can potentially allow unauthorized access or manipulation of data in the affected Siemens software applications.