CVE-2024-54094

A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 5). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:solid_edge_se2024:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0001:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0002:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0003:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0004:*:*:*:*:*:*

History

04 Mar 2025, 18:19

Type Values Removed Values Added
First Time Siemens solid Edge Se2024
Siemens
CPE cpe:2.3:a:siemens:solid_edge_se2024:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:-:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0002:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0003:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0004:*:*:*:*:*:*
cpe:2.3:a:siemens:solid_edge_se2024:224.0:update_0001:*:*:*:*:*:*
References () https://cert-portal.siemens.com/productcert/html/ssa-730188.html - () https://cert-portal.siemens.com/productcert/html/ssa-730188.html - Vendor Advisory
Summary
  • (es) Se ha identificado una vulnerabilidad en Solid Edge SE2024 (todas las versiones anteriores a V224.0 Update 5). La aplicación afectada es vulnerable a un desbordamiento de búfer de almacenamiento dinámico al analizar archivos PAR especialmente manipulados. Esto podría permitir que un atacante ejecute código en el contexto del proceso actual.
CWE CWE-787

10 Dec 2024, 14:30

Type Values Removed Values Added
New CVE

Information

Published : 2024-12-10 14:30

Updated : 2025-03-04 18:19


NVD link : CVE-2024-54094

Mitre link : CVE-2024-54094

CVE.ORG link : CVE-2024-54094


JSON object : View

Products Affected

siemens

  • solid_edge_se2024
CWE
CWE-122

Heap-based Buffer Overflow

CWE-787

Out-of-bounds Write