As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens’ ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
1. EXECUTIVE SUMMARY
- CVSS v3 7.3
- ATTENTION: Low Attack Complexity
- Vendor: Siemens
- Equipment: Parasolid
- Vulnerabilities: Out-of-bounds Read, NULL Pointer Dereference
2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to execute code in the context of the current process and crash the application causing a denial-of-service condition.
3. TECHNICAL DETAILS
3.1 AFFECTED PRODUCTS
The following versions of Siemens Parasolid, a design and simulation product, are affected:
- Siemens Parasolid V35.1: Versions prior to V35.1.256
- Siemens Parasolid V36.0: Versions prior to V36.0.208
- Siemens Parasolid V36.1: Versions prior to V36.1.173
3.2 Vulnerability Overview
3.2.1 OUT-OF-BOUNDS READ CWE-125
The affected applications contain an out-of-bounds read past the unmapped memory region while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.
CVE-2024-32635 has been assigned to this vulnerability. A CVSS v3 base score of 7.8 has been assigned; the CVSS vector string is (CVSS:3.1/AV
[…]
Content was cut in order to protect the source.Please visit the source for the rest of the article.
Read the original article: