

North Korean IT Workers Now Demand Ransom for Stolen Data
October 21, 2024
Researchers Find Critical Vulnerabilities in Leading E2EE Cloud Storage Companies
October 21, 2024
North Korean IT Workers Now Demand Ransom for Stolen Data
October 21, 2024
Researchers Find Critical Vulnerabilities in Leading E2EE Cloud Storage Companies
October 21, 2024Severity
High
Analysis Summary
CVE-2024-45469 CVSS:7.8
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file. This could allow an attacker to execute code in the context of the current process.
CVE-2024-45470 CVSS:7.8
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file. This could allow an attacker to execute code in the context of the current process.
CVE-2024-45471 CVSS:7.8
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted WRL file. This could allow an attacker to execute code in the context of the current process.
CVE-2024-45472 CVSS:7.8
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.
CVE-2024-45473 CVSS:7.8
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.
CVE-2024-45474 CVSS:7.8
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.
CVE-2024-45475 CVSS:7.8
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected application is vulnerable to memory corruption while parsing specially crafted WRL files. An attacker could leverage this in conjunction with other vulnerabilities to execute code in the context of the current process.
CVE-2024-45476 CVSS:3.3
A vulnerability has been identified in Tecnomatix Plant Simulation V2302 (All versions < V2302.0016), Tecnomatix Plant Simulation V2404 (All versions < V2404.0005). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted WRL files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.
Impact
- Denial of Service
- Code Execution
Indicators of Compromise
CVE
- CVE-2024-45469
- CVE-2024-45470
- CVE-2024-45471
- CVE-2024-45472
- CVE-2024-45473
- CVE-2024-45474
- CVE-2024-45475
- CVE-2024-45476
Affected Vendors
Affected Products
- Siemens Tecnomatix Plant Simulation V2302
- Siemens Tecnomatix Plant Simulation V2404
Remediation
Refer to Siemens Security Advisory for patch, upgrade, or suggested workaround information.