CVE-2024-37997: High severity jt open vulnerability
A vulnerability has been identified in JT Open (All versions < V11.5), JT2Go (All versions < V2406.0003), PLM XML SDK (All versions < V7.1.0.014), Teamcenter Visualization V14.2 (All versions < V14.2.0.13), Teamcenter Visualization V14.3 (All versions < V14.3.0.11), Teamcenter Visualization V2312 (All versions < V2312.0008), Teamcenter Visualization V2406 (All versions < V2406.0003). The affected applications contain a stack based overflow vulnerability while parsing specially crafted XML files. This could allow an attacker to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37997?
CVE-2024-37997 is classified as a critical vulnerability due to its potential impact on affected software.
How do I fix CVE-2024-37997?
To fix CVE-2024-37997, update your software to the latest version as specified in the vendor's security advisories.
Which versions are affected by CVE-2024-37997?
CVE-2024-37997 affects all versions of JT Open below 11.5, JT2Go below 2406.0003, PLM XML SDK below 7.1.0.014, and specific versions of Teamcenter Visualization.
What products are impacted by CVE-2024-37997?
CVE-2024-37997 impacts JT Open, Siemens JT2Go, Siemens PLM XML SDK, and various versions of Siemens Teamcenter Visualization.
Is there a workaround for CVE-2024-37997?
There are no known workarounds for CVE-2024-37997, so applying the necessary updates is the recommended action.