PT-2024-2997 · Siemens · Parasolid+2

Jin Huang

·

Published

2024-04-09

·

Updated

2024-08-13

·

CVE-2024-26277

CVSS v3.1

3.3

Low

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L
Name of the Vulnerable Software and Affected Versions Parasolid versions prior to V35.1.254 Parasolid versions prior to V36.0.207 Parasolid versions prior to V36.1.147 JT2Go versions prior to V2312.0004 Teamcenter Visualization versions prior to V14.2.0.12 Teamcenter Visualization versions prior to V14.3.0.9 Teamcenter Visualization versions prior to V2312.0004
Description The issue is related to a null pointer dereference vulnerability. This vulnerability can be exploited by an attacker using specially crafted X T files, potentially leading to a denial of service condition by crashing the application.
Recommendations For Parasolid versions prior to V35.1.254, update to version V35.1.254 or later. For Parasolid versions prior to V36.0.207, update to version V36.0.207 or later. For Parasolid versions prior to V36.1.147, update to version V36.1.147 or later. For JT2Go versions prior to V2312.0004, update to version V2312.0004 or later. For Teamcenter Visualization versions prior to V14.2.0.12, update to version V14.2.0.12 or later. For Teamcenter Visualization versions prior to V14.3.0.9, update to version V14.3.0.9 or later. For Teamcenter Visualization versions prior to V2312.0004, update to version V2312.0004 or later.

Fix

NULL Pointer Dereference

Weakness Enumeration

Related Identifiers

BDU:2024-03177
CVE-2024-26277

Affected Products

Jt2Go
Parasolid
Teamcenter Visualization