CVE-2024-34771

A

vulnerability has been identified in Solid Edge (All versions < V224.0 Update 2). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:solid_edge_se2024:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0001:*:*:*:*:*:*

History

07 Mar 2025, 16:00

Type Values Removed Values Added
CWE CWE-787
CPE cpe:2.3:a:siemens:solid_edge_se2024:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0001:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-589937.html - () https://cert-portal.siemens.com/productcert/html/ssa-589937.html - Vendor Advisory
First Time Siemens
Siemens solid Edge Se2024

21 Nov 2024, 09:19

Type Values Removed Values Added
Summary
  • (es) Se ha identificado una vulnerabilidad en Solid Edge (Todas las versiones &lt; V224.0 Actualización 2). La aplicación afectada es vulnerable al desbordamiento de búfer de almacenamiento dinámico mientras analiza archivos PAR especialmente manipulados. Esto podría permitir a un atacante ejecutar código en el contexto del proceso actual.
References () https://cert-portal.siemens.com/productcert/html/ssa-589937.html - () https://cert-portal.siemens.com/productcert/html/ssa-589937.html -

14 May 2024, 16:17

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-14 16:17

Updated : 2025-03-07 16:00


NVD link : CVE-2024-34771

Mitre link : CVE-2024-34771

CVE.ORG link : CVE-2024-34771


JSON object : View

Products Affected
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write