Rewterz
North Korean IT Workers Now Demand Ransom for Stolen Data
October 21, 2024
Rewterz
Researchers Find Critical Vulnerabilities in Leading E2EE Cloud Storage Companies
October 21, 2024

ICS: Multiple Siemens Products Vulnerabilities

Severity

High

Analysis Summary

CVE-2024-45469 CVSS:7.8

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file. This could allow an attacker to execute code in the context of the current process.

CVE-2024-45470 CVSS:7.8

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file. This could allow an attacker to execute code in the context of the current process.

CVE-2024-45471 CVSS:7.8

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file. This could allow an attacker to execute code in the context of the current process.

CVE-2024-45472 CVSS:7.8

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVE-2024-45473 CVSS:7.8

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVE-2024-45474 CVSS:7.8

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVE-2024-45475 CVSS:7.8

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.

CVE-2024-45476 CVSS:3.3

A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted WRL files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

Impact

  • Denial of Service
  • Code Execution

Indicators of Compromise

CVE

  • CVE-2024-45469
  • CVE-2024-45470
  • CVE-2024-45471
  • CVE-2024-45472
  • CVE-2024-45473
  • CVE-2024-45474
  • CVE-2024-45475
  • CVE-2024-45476

Affected Vendors

Siemens

Affected Products

  • Siemens Tecnomatix Plant Simulation V2302
  • Siemens Tecnomatix Plant Simulation V2404

Remediation

Refer to Siemens Security Advisory for patch, upgrade, or suggested workaround information.

Siemens Security Advisory