PT-2024-8715 · Siemens · Solid Edge
Nafiez
·
Published
2024-11-12
·
Updated
2026-02-19
·
CVE-2024-47942
CVSS v3.1
7.3
High
| Vector | AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Solid Edge SE2024 versions prior to V224.0 Update 9
Description
A DLL hijacking issue has been identified, which could allow an attacker to execute arbitrary code by placing a crafted DLL file on the system. The vulnerability is related to an uncontrolled search path element.
Recommendations
For versions prior to V224.0 Update 9, update to V224.0 Update 9 or later to resolve the issue. As a temporary workaround, consider restricting access to the system to minimize the risk of exploitation. Avoid placing untrusted DLL files in the system to prevent potential attacks.
Fix
Uncontrolled Search Path Element
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Solid Edge