CVE-2023-45204

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Oct 10, 2023
Updated: Oct 12, 2023
CWE ID 704

Summary

CVE-2023-45204 is a type confusion vulnerability affecting Tecnomatix Plant Simulation V2201 (versions below V2201.0009) and V2302 (versions below V2302.0003). Maliciously crafted IGS files can exploit this issue, leading to arbitrary code execution in the context of the current process. (ZDI-CAN-21268) This vulnerability poses a significant risk, as an attacker could potentially gain unauthorized access to sensitive data or take control of the affected system. It is crucial that users upgrade to the patched versions of Tecnomatix Plant Simulation as soon as possible to mitigate this threat.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Siemens Tecnomatix

Affected Vendors

  • Siemens AG