CVE-2024-35303: Incorrect Type Cast
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0012), Tecnomatix Plant Simulation V2404 (All versions < V2404.0001). The affected applications contain a type confusion vulnerability while parsing specially crafted MODEL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-22958)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-35303?
CVE-2024-35303 is classified as a critical vulnerability due to its potential to allow remote code execution through specially crafted MODEL files.
How do I fix CVE-2024-35303?
To mitigate CVE-2024-35303, upgrade to Tecnomatix Plant Simulation V2302.0012 or V2404.0001 or later versions.
What products are affected by CVE-2024-35303?
CVE-2024-35303 affects Tecnomatix Plant Simulation V2302 and V2404 before their respective fixed versions.
What type of vulnerability is CVE-2024-35303?
CVE-2024-35303 is a type confusion vulnerability that occurs while parsing specially crafted MODEL files.
Can CVE-2024-35303 lead to data exposure?
Yes, CVE-2024-35303 can potentially lead to unauthorized access and manipulation of sensitive data if exploited.