CVE-2024-33489

A vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0001:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0002:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0003:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0004:*:*:*:*:*:*

History

07 Mar 2025, 14:55

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
References () https://cert-portal.siemens.com/productcert/html/ssa-589937.html - () https://cert-portal.siemens.com/productcert/html/ssa-589937.html - Vendor Advisory
First Time Siemens solid Edge Se2024
Siemens
CPE cpe:2.3:a:siemens:solid_edge_se2024:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0001:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0004:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0002:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0003:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:-:*:*:*:*:*:*

14 May 2024, 19:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 16:17

Updated : 2025-03-07 14:55


NVD link : CVE-2024-33489

Mitre link : CVE-2024-33489


JSON object : View

Products Affected

siemens

  • solid_edge_se2024
CWE

No CWE.