CVE-2024-54091: A vulnerability has been identified in Parasolid V36.1 (All versions < V36.1.225), Parasolid V37.0 (All versions < V37.0.173), Parasolid V37.1 (All...

7.8 CVSS

Description

A vulnerability has been identified in Parasolid V36.1 (All versions < V36.1.225), Parasolid V37.0 (All versions < V37.0.173), Parasolid V37.1 (All versions < V37.1.109). The affected applications contain an out of bounds write vulnerability when parsing specially crafted PAR files.
This could allow an attacker to execute code in the context of the current process.

Classification

CVE ID: CVE-2024-54091

CVSS Base Severity: HIGH

CVSS Base Score: 7.8

Affected Products

Vendor: Siemens

Product: Parasolid V36.1

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.48% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://cert-portal.siemens.com/productcert/html/ssa-979056.html

Timeline