CVE Vulnerabilities

CVE-2024-32637

NULL Pointer Dereference

Published: May 14, 2024 | Modified: Oct 03, 2025
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu
root.io logo minimus.io logo echo.ai logo

A vulnerability has been identified in JT2Go (All versions < V2312.0005), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.10), Teamcenter Visualization V2312 (All versions < V2312.0005). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted X_T files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

Weakness

The product dereferences a pointer that it expects to be valid but is NULL.

Affected Software

NameVendorStart VersionEnd Version
Jt2goSiemens2312.0 (including)2312.0005 (excluding)
ParasolidSiemens35.0 (including)35.1.256 (excluding)
ParasolidSiemens36.0 (including)36.0.208 (excluding)
ParasolidSiemens36.1 (including)36.1.173 (excluding)
Teamcenter_visualizationSiemens14.2 (including)14.2.0.12 (excluding)
Teamcenter_visualizationSiemens14.3 (including)14.3.0.10 (excluding)
Teamcenter_visualizationSiemens2312.0 (including)2312.0005 (excluding)

Potential Mitigations

References