CVE-2024-33489

A

vulnerability has been identified in Solid Edge (All versions < V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:solid_edge_se2024:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0001:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0002:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0003:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0004:*:*:*:*:*:*

History

07 Mar 2025, 15:59

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0003:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0001:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0002:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0004:*:*:*:*:*:*
First Time Siemens
Siemens solid Edge Se2024
CWE CWE-787
References () https://cert-portal.siemens.com/productcert/html/ssa-589937.html - () https://cert-portal.siemens.com/productcert/html/ssa-589937.html - Vendor Advisory

21 Nov 2024, 09:17

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en Solid Edge (Todas las versiones &lt; V224.0 Actualización 5). La aplicación afectada es vulnerable al desbordamiento de búfer de almacenamiento dinámico mientras analiza archivos PAR especialmente manipulados. Esto podría permitir a un atacante ejecutar código en el contexto del proceso actual.
References () https://cert-portal.siemens.com/productcert/html/ssa-589937.html - () https://cert-portal.siemens.com/productcert/html/ssa-589937.html -

14 May 2024, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 16:17

Updated : 2025-03-07 15:59


NVD link : CVE-2024-33489

Mitre link : CVE-2024-33489

CVE.ORG link : CVE-2024-33489


JSON object : View

Products Affected
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write