CVE Vulnerabilities

CVE-2024-32637

NULL Pointer Dereference

Published: May 14, 2024 | Modified: Oct 03, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.10), Teamcenter Visualization V2312 (All versions < V2312.0005). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted X_T files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

Name Vendor Start Version End Version
Jt2go Siemens 2312.0 (including) 2312.0005 (excluding)
Parasolid Siemens 35.0 (including) 35.1.256 (excluding)
Parasolid Siemens 36.0 (including) 36.0.208 (excluding)
Parasolid Siemens 36.1 (including) 36.1.173 (excluding)
Teamcenter_visualization Siemens 14.2 (including) 14.2.0.12 (excluding)
Teamcenter_visualization Siemens 14.3 (including) 14.3.0.10 (excluding)
Teamcenter_visualization Siemens 2312.0 (including) 2312.0005 (excluding)

Potential Mitigations

References