First published: Tue Dec 10 2024(Updated: )
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 12), Solid Edge SE2025 (All versions < V225.0 Update 3). The affected application contains an out of bounds write past the end of an allocated buffer while parsing X_T data or a specially crafted file in X_T format. This could allow an attacker to execute code in the context of the current process.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Solid Edge | <V224.0 Update 12 | |
Siemens Solid Edge SE2025 | <V225.0 Update 3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-54091 has been classified as a high severity vulnerability due to the potential for exploitation via specially crafted X_T files.
To fix CVE-2024-54091, update Siemens Parasolid to version 36.1.225 or 37.0.173 or later.
CVE-2024-54091 affects all versions of Siemens Parasolid prior to 36.1.225 and 37.0.173.
Attackers can exploit CVE-2024-54091 by crafting malicious X_T files that trigger an out-of-bounds write.
Yes, CVE-2024-54091 has been resolved in patches released with versions 36.1.225 and 37.0.173 of Siemens Parasolid.