PT-2024-2693 · Siemens · Tecnomatix Plant Simulation

Nafiez

·

Published

2024-01-03

·

Updated

2024-02-13

·

CVE-2024-23800

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Tecnomatix Plant Simulation versions V2201 through V2302.0006
Description The issue is related to a null pointer dereference vulnerability. This vulnerability can be exploited by an attacker using specially crafted SPP files, potentially causing a denial of service condition by crashing the application.
Recommendations For Tecnomatix Plant Simulation version V2201, update to a version newer than V2201. For Tecnomatix Plant Simulation version V2302, update to version V2302.0007 or newer. As a temporary workaround, consider restricting the use of specially crafted SPP files to minimize the risk of exploitation.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2024-02804
CVE-2024-23800

Affected Products

Tecnomatix Plant Simulation