CVE-2022-24290

Description

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9), Teamcenter V13.1 (All versions), Teamcenter V13.2 (All versions < V13.2.0.8), Teamcenter V13.3 (All versions < V13.3.0.3), Teamcenter V14.0 (All versions < V14.0.0.2). The tcserver.exe binary in affected applications is vulnerable to a stack overflow condition during the parsing of user input that may lead the binary to crash.

Risk Information

Base Score
7.5
MODERATE
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
EPSS Score
Exploitation Probability
0.751

Associated Vulnerability

VulnerabilityOS Platform
Multiple Vulnerabilities are affected in Siemens Teamcenter Visualization 13.0.0Windows
Vulnerabilities CVE-2021-27390,CVE-2022-24290 are affected in Siemens Teamcenter Visualization 13.1.0.2Windows
Multiple Vulnerabilities are affected in Siemens Teamcenter Visualization 12.4.0Windows
Multiple Vulnerabilities are affected in Siemens Teamcenter Visualization 13.3.0Windows
Multiple Vulnerabilities are affected in Siemens Teamcenter Visualization 13.2.0Windows
Vulnerabilities CVE-2022-24290,CVE-2022-31619,CVE-2022-34660,CVE-2022-34661 are affected in Siemens Teamcenter 14.0Windows

Patch Details

No records found

References

https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234