Lucene search

K
nvd[email protected]NVD:CVE-2024-23800
HistoryFeb 13, 2024 - 9:15 a.m.

CVE-2024-23800

2024-02-1309:15:48
CWE-476
web.nvd.nist.gov
5
vulnerability
tecnomatix plant simulation
spp files
denial of service

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

4.7

Confidence

High

EPSS

0

Percentile

12.7%

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted SPP files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

Affected configurations

Nvd
Node
siemenstecnomatix_plant_simulationRange2302.02302.0007
OR
siemenstecnomatix_plant_simulationMatch2201.0-
VendorProductVersionCPE
siemenstecnomatix_plant_simulation*cpe:2.3:a:siemens:tecnomatix_plant_simulation:*:*:*:*:*:*:*:*
siemenstecnomatix_plant_simulation2201.0cpe:2.3:a:siemens:tecnomatix_plant_simulation:2201.0:-:*:*:*:*:*:*

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

AI Score

4.7

Confidence

High

EPSS

0

Percentile

12.7%

Related for NVD:CVE-2024-23800