CVE-2014-2073
Description
Stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 allows remote attackers to execute arbitrary code via a crafted packet, related to "CATV5_Backbone_Bus."
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Unauthenticated remote attackers can trigger a stack-based buffer overflow in Dassault Systemes CATIA V5-6R2013 via a crafted packet on the CATV5_Backbone_Bus, leading to arbitrary code execution.
Vulnerability
A stack-based buffer overflow exists in Dassault Systemes CATIA V5-6R2013, specifically within the "CATV5_Backbone_Bus" component. The vulnerability is triggered when the application processes a specially crafted network packet. No authentication is required to reach the vulnerable code path, making it remotely exploitable over the network. The affected version is CATIA V5-6R2013; earlier or later versions may not be vulnerable, though this is not explicitly stated in the references [1].
Exploitation
An attacker needs only network access to a machine running the vulnerable CATIA installation. No prior authentication or user interaction is required. The exploit involves sending a crafted packet to the service that handles the CATV5_Backbone_Bus protocol. The packet contains data that overflows a fixed-size stack buffer, overwriting critical control flow structures such as the saved return address. Proof-of-concept code is publicly available, as noted in reference [1].
Impact
Successful exploitation allows an attacker to execute arbitrary code with the privileges of the CATIA process. This typically leads to full system compromise, including the ability to read, modify, or delete data, install malware, or pivot to other systems on the network. The vulnerability is classified as a remote code execution (RCE) flaw affecting the confidentiality, integrity, and availability of the compromised system [1].
Mitigation
As of the publication date of reference [1] (April 2014), Dassault Systemes had not released a security patch or advisory for this vulnerability. The product may remain vulnerable unless an update was provided later. No workaround is documented in the available references. The CVE is not listed in the Known Exploited Vulnerabilities (KEV) catalog. Users should verify with the vendor for any post-2014 fixes or consider network-level controls to restrict access to the vulnerable service [1].
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
1Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- packetstormsecurity.com/files/125325/Catia-V5-6R2013-Stack-Buffer-Overflow.htmlmitrex_refsource_MISC
News mentions
0No linked articles in our index yet.