ZDI-CAN-25205: ZDI-25-057: Siemens Tecnomatix Plant Simulation WRL File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-45471.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-25205?
The severity of ZDI-CAN-25205 is critical as it allows remote code execution on affected systems.
How do I fix ZDI-CAN-25205?
To fix ZDI-CAN-25205, update your Siemens Tecnomatix Plant Simulation software to the latest version provided by Siemens.
What software is affected by ZDI-CAN-25205?
ZDI-CAN-25205 affects installations of Siemens Tecnomatix Plant Simulation.
What are the attack vector details for ZDI-CAN-25205?
ZDI-CAN-25205 requires user interaction, as the target must visit a malicious webpage or open a harmful file.
Can ZDI-CAN-25205 be exploited without user interaction?
No, ZDI-CAN-25205 cannot be exploited without user interaction.