High severity7.8NVD Advisory· Published Oct 10, 2023· Updated Jun 17, 2026
CVE-2023-45601
CVE-2023-45601
Description
A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.262), Parasolid V35.1 (All versions < V35.1.250), Parasolid V36.0 (All versions < V36.0.169), Tecnomatix Plant Simulation V2201 (All versions < V2201.0009), Tecnomatix Plant Simulation V2302 (All versions < V2302.0003). The affected applications contain a stack overflow vulnerability while parsing specially crafted IGS files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21290)
Affected products
9cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:*range: >=35.0,<35.0.262
- (no CPE)range: < V35.0.262, < V35.1.250, < V36.0.169
< V2201.0009, < V2302.0003+ 2 more
- (no CPE)range: < V2201.0009, < V2302.0003
- (no CPE)range: All versions < V2201.0009
- (no CPE)range: All versions < V2302.0003
- Siemens/Parasolid V35.0v5Range: All versions < V35.0.262
- Siemens/Parasolid V35.1v5Range: All versions < V35.1.250
- Siemens/Parasolid V36.0v5Range: All versions < V36.0.169
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-524778.pdfnvdPatchVendor Advisory
News mentions
0No linked articles in our index yet.