CVE Vulnerabilities

CVE-2023-38524

NULL Pointer Dereference

Published: Aug 08, 2023 | Modified: Nov 21, 2024
CVSS 3.x
7.8
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35.1 (All versions < V35.1.171), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.3). The affected applications contain null pointer dereference while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Parasolid Siemens 34.1 (including) 34.1.258 (excluding)
Parasolid Siemens 35.0 (including) 35.0.254 (excluding)
Parasolid Siemens 35.1 (including) 35.1.171 (excluding)
Teamcenter_visualization Siemens 14.1 (including) 14.1.0.11 (excluding)
Teamcenter_visualization Siemens 14.2 (including) 14.2.0.6 (excluding)
Teamcenter_visualization Siemens 14.3 (including) 14.3.0.3 (excluding)

Potential Mitigations

References