2024-05-14 18:03:25 +00:00
{
"id" : "CVE-2024-33577" ,
"sourceIdentifier" : "productcert@siemens.com" ,
"published" : "2024-05-14T16:17:20.707" ,
2024-12-08 03:06:42 +00:00
"lastModified" : "2024-11-21T09:17:11.297" ,
2024-05-14 20:03:30 +00:00
"vulnStatus" : "Awaiting Analysis" ,
2024-07-09 14:03:16 +00:00
"cveTags" : [ ] ,
2024-05-14 18:03:25 +00:00
"descriptions" : [
{
"lang" : "en" ,
2024-07-09 14:03:16 +00:00
"value" : "A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process."
2024-05-19 02:03:31 +00:00
} ,
{
"lang" : "es" ,
"value" : "Se ha identificado una vulnerabilidad en Simcenter Nastran 2306 (Todas las versiones), Simcenter Nastran 2312 (Todas las versiones), Simcenter Nastran 2406 (Todas las versiones < V2406.90). Las aplicaciones afectadas contienen una vulnerabilidad de desbordamiento de pila al analizar cadenas especiales como argumento para uno de los archivos binarios de la aplicaci\u00f3n. Esto podr\u00eda permitir a un atacante ejecutar c\u00f3digo en el contexto del proceso actual."
2024-05-14 18:03:25 +00:00
}
] ,
"metrics" : {
2024-07-09 14:03:16 +00:00
"cvssMetricV40" : [
{
"source" : "productcert@siemens.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "4.0" ,
"vectorString" : "CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 7.3 ,
"baseSeverity" : "HIGH" ,
2024-07-09 14:03:16 +00:00
"attackVector" : "LOCAL" ,
"attackComplexity" : "HIGH" ,
"attackRequirements" : "NONE" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "PASSIVE" ,
"vulnerableSystemConfidentiality" : "HIGH" ,
"vulnerableSystemIntegrity" : "HIGH" ,
"vulnerableSystemAvailability" : "HIGH" ,
"subsequentSystemConfidentiality" : "NONE" ,
"subsequentSystemIntegrity" : "NONE" ,
"subsequentSystemAvailability" : "NONE" ,
"exploitMaturity" : "NOT_DEFINED" ,
"confidentialityRequirements" : "NOT_DEFINED" ,
"integrityRequirements" : "NOT_DEFINED" ,
"availabilityRequirements" : "NOT_DEFINED" ,
"modifiedAttackVector" : "NOT_DEFINED" ,
"modifiedAttackComplexity" : "NOT_DEFINED" ,
"modifiedAttackRequirements" : "NOT_DEFINED" ,
"modifiedPrivilegesRequired" : "NOT_DEFINED" ,
"modifiedUserInteraction" : "NOT_DEFINED" ,
"modifiedVulnerableSystemConfidentiality" : "NOT_DEFINED" ,
"modifiedVulnerableSystemIntegrity" : "NOT_DEFINED" ,
"modifiedVulnerableSystemAvailability" : "NOT_DEFINED" ,
"modifiedSubsequentSystemConfidentiality" : "NOT_DEFINED" ,
"modifiedSubsequentSystemIntegrity" : "NOT_DEFINED" ,
"modifiedSubsequentSystemAvailability" : "NOT_DEFINED" ,
"safety" : "NOT_DEFINED" ,
"automatable" : "NOT_DEFINED" ,
"recovery" : "NOT_DEFINED" ,
"valueDensity" : "NOT_DEFINED" ,
"vulnerabilityResponseEffort" : "NOT_DEFINED" ,
2024-12-08 03:06:42 +00:00
"providerUrgency" : "NOT_DEFINED"
2024-07-09 14:03:16 +00:00
}
}
] ,
2024-05-14 18:03:25 +00:00
"cvssMetricV31" : [
{
"source" : "productcert@siemens.com" ,
"type" : "Secondary" ,
"cvssData" : {
"version" : "3.1" ,
"vectorString" : "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H" ,
2024-12-08 03:06:42 +00:00
"baseScore" : 7.8 ,
"baseSeverity" : "HIGH" ,
2024-05-14 18:03:25 +00:00
"attackVector" : "LOCAL" ,
"attackComplexity" : "LOW" ,
"privilegesRequired" : "NONE" ,
"userInteraction" : "REQUIRED" ,
"scope" : "UNCHANGED" ,
"confidentialityImpact" : "HIGH" ,
"integrityImpact" : "HIGH" ,
2024-12-08 03:06:42 +00:00
"availabilityImpact" : "HIGH"
2024-05-14 18:03:25 +00:00
} ,
"exploitabilityScore" : 1.8 ,
"impactScore" : 5.9
}
]
} ,
"weaknesses" : [
{
"source" : "productcert@siemens.com" ,
2024-12-08 03:06:42 +00:00
"type" : "Secondary" ,
2024-05-14 18:03:25 +00:00
"description" : [
{
"lang" : "en" ,
"value" : "CWE-121"
}
]
}
] ,
"references" : [
2024-07-09 14:03:16 +00:00
{
"url" : "https://cert-portal.siemens.com/productcert/html/ssa-064222.html" ,
"source" : "productcert@siemens.com"
} ,
2024-05-14 18:03:25 +00:00
{
"url" : "https://cert-portal.siemens.com/productcert/html/ssa-258494.html" ,
"source" : "productcert@siemens.com"
2024-12-08 03:06:42 +00:00
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/html/ssa-064222.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
} ,
{
"url" : "https://cert-portal.siemens.com/productcert/html/ssa-258494.html" ,
"source" : "af854a3a-2127-422b-91ae-364da2661108"
2024-05-14 18:03:25 +00:00
}
]
}