VYPR
Unrated severityNVD Advisory· Published May 14, 2024· Updated Aug 2, 2024

CVE-2024-31980

CVE-2024-31980

Description

A vulnerability has been identified in Parasolid V35.1 (All versions < V35.1.256), Parasolid V36.0 (All versions < V36.0.210), Parasolid V36.1 (All versions < V36.1.185). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted X_T part file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-23468)

Affected products

4
  • Range: < V35.1.256, < V36.0.210, < V36.1.185
  • Siemens/Parasolid V35.1v5
    Range: 0
  • Siemens/Parasolid V36.0v5
    Range: 0
  • Siemens/Parasolid V36.1v5
    Range: 0

Patches

0

No patches discovered yet.

Vulnerability mechanics

No source-code context for this CVE — mechanics is only generated when we can read the actual fix diff. Without that, the four sections (root cause, attack vector, affected code, fix) would be speculation rather than analysis.

References

1

News mentions

0

No linked articles in our index yet.