CVE-2024-54091

A

vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 12), Solid Edge SE2025 (All versions < V225.0 Update 3). The affected application contains an out of bounds write past the end of an allocated buffer while parsing X_T data or a specially crafted file in X_T format. This could allow an attacker to execute code in the context of the current process.

Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0001:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_00010:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_00011:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0002:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0003:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0004:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0005:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0006:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0007:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0008:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0009:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2025:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2025:225.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2025:225.0:update_0001:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2025:225.0:update_0002:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2025:225.0:update_0003:*:*:*:*:*:*

History

29 Oct 2025, 14:21

Type Values Removed Values Added
First Time Siemens
Siemens solid Edge Se2024
Siemens parasolid
Siemens solid Edge Se2025
CPE cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0005:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_00011:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0003:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0008:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2025:225.0:update_0003:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0007:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0004:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2025:225.0:update_0001:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2025:225.0:update_0002:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2025:225.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0009:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2025:-:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_00010:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0001:*:*:*:*:*:*
cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0002:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0006:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-672923.html - () https://cert-portal.siemens.com/productcert/html/ssa-672923.html - Vendor Advisory
References () https://cert-portal.siemens.com/productcert/html/ssa-979056.html - () https://cert-portal.siemens.com/productcert/html/ssa-979056.html - Vendor Advisory

08 Apr 2025, 09:15

Type Values Removed Values Added
References
  • () https://cert-portal.siemens.com/productcert/html/ssa-672923.html -
Summary (en) A vulnerability has been identified in Parasolid V36.1 (All versions < V36.1.225), Parasolid V37.0 (All versions < V37.0.173). The affected application contains an out of bounds write past the end of an allocated buffer while parsing X_T data or a specially crafted file in X_T format. This could allow an attacker to execute code in the context of the current process. (en) A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 12), Solid Edge SE2025 (All versions < V225.0 Update 3). The affected application contains an out of bounds write past the end of an allocated buffer while parsing X_T data or a specially crafted file in X_T format. This could allow an attacker to execute code in the context of the current process.

12 Dec 2024, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 14:30

Updated : 2025-10-29 14:21


NVD link : CVE-2024-54091

Mitre link : CVE-2024-54091

CVE.ORG link : CVE-2024-54091


JSON object : View

CWE
CWE-787

Out-of-bounds Write