PT-2024-7986 · Siemens · Simcenter Nastran+1
Michael Heinzl
·
Published
2024-10-08
·
Updated
2024-12-10
·
CVE-2024-41981
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Simcenter Femap versions V2306 through V2406
Simcenter Nastran versions 2306 through 2312
Description
The issue is related to a heap-based buffer overflow in the BDF File Handler component. This occurs when the application parses specially crafted BDF files, potentially allowing an attacker to execute arbitrary code in the context of the current process.
Recommendations
For Simcenter Femap versions V2306 through V2406, avoid using the BDF File Handler component until a patch is available.
For Simcenter Nastran versions 2306 through 2312, restrict access to the BDF file parsing functionality to minimize the risk of exploitation.
As a temporary workaround, consider disabling the BDF file handling feature in both Simcenter Femap and Simcenter Nastran until a fix is provided.
Fix
Heap Based Buffer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Simcenter Femap
Simcenter Nastran