First published: Tue Oct 08 2024(Updated: )
A vulnerability has been identified in Teamcenter Visualization V14.2 (All versions < V14.2.0.14), Teamcenter Visualization V14.3 (All versions < V14.3.0.12), Teamcenter Visualization V2312 (All versions < V2312.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Tecnomatix Plant Simulation | <2302.0016 | |
Siemens Tecnomatix Plant Simulation | >=2303.0000<2404.0005 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-45473 is classified as a high-severity vulnerability affecting certain versions of Siemens software.
To remediate CVE-2024-45473, upgrade to the specified fixed versions of Teamcenter Visualization and Tecnomatix Plant Simulation.
CVE-2024-45473 affects Teamcenter Visualization versions prior to V14.2.0.14, V14.3.0.12, V2312.0008, and Tecnomatix Plant Simulation versions prior to V2302.0016.
If you are using any affected versions of Teamcenter Visualization or Tecnomatix Plant Simulation, your software is vulnerable to CVE-2024-45473.
Currently, upgrading to the fixed versions is the recommended approach to mitigate CVE-2024-45473, and no formal workarounds have been provided.