PT-2024-7986 · Siemens · Simcenter Nastran+1

Michael Heinzl

·

Published

2024-10-08

·

Updated

2024-12-10

·

CVE-2024-41981

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simcenter Femap versions V2306 through V2406 Simcenter Nastran versions 2306 through 2312
Description The issue is related to a heap-based buffer overflow in the BDF File Handler component. This occurs when the application parses specially crafted BDF files, potentially allowing an attacker to execute arbitrary code in the context of the current process.
Recommendations For Simcenter Femap versions V2306 through V2406, avoid using the BDF File Handler component until a patch is available. For Simcenter Nastran versions 2306 through 2312, restrict access to the BDF file parsing functionality to minimize the risk of exploitation. As a temporary workaround, consider disabling the BDF file handling feature in both Simcenter Femap and Simcenter Nastran until a fix is provided.

Fix

Heap Based Buffer Overflow

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-09500
CVE-2024-41981

Affected Products

Simcenter Femap
Simcenter Nastran