PT-2024-2997 · Siemens · Parasolid+2
Jin Huang
·
Published
2024-04-09
·
Updated
2024-08-13
·
CVE-2024-26277
CVSS v3.1
3.3
Low
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:L |
Name of the Vulnerable Software and Affected Versions
Parasolid versions prior to V35.1.254
Parasolid versions prior to V36.0.207
Parasolid versions prior to V36.1.147
JT2Go versions prior to V2312.0004
Teamcenter Visualization versions prior to V14.2.0.12
Teamcenter Visualization versions prior to V14.3.0.9
Teamcenter Visualization versions prior to V2312.0004
Description
The issue is related to a null pointer dereference vulnerability. This vulnerability can be exploited by an attacker using specially crafted X T files, potentially leading to a denial of service condition by crashing the application.
Recommendations
For Parasolid versions prior to V35.1.254, update to version V35.1.254 or later.
For Parasolid versions prior to V36.0.207, update to version V36.0.207 or later.
For Parasolid versions prior to V36.1.147, update to version V36.1.147 or later.
For JT2Go versions prior to V2312.0004, update to version V2312.0004 or later.
For Teamcenter Visualization versions prior to V14.2.0.12, update to version V14.2.0.12 or later.
For Teamcenter Visualization versions prior to V14.3.0.9, update to version V14.3.0.9 or later.
For Teamcenter Visualization versions prior to V2312.0004, update to version V2312.0004 or later.
Fix
NULL Pointer Dereference
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Jt2Go
Parasolid
Teamcenter Visualization