CVE-2024-54091
HIGHDescription
A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 12), Solid Edge SE2025 (All versions < V225.0 Update 3). The affected application contains an out of bounds write past the end of an allocated buffer while parsing X_T data or a specially crafted file in X_T format. This could allow an attacker to execute code in the context of the current process.
Is your site exposed to CVE-2024-54091?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| siemens | parasolid |
| siemens | parasolid |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2024 |
| siemens | solid_edge_se2025 |
| siemens | solid_edge_se2025 |
| siemens | solid_edge_se2025 |
| siemens | solid_edge_se2025 |
| siemens | solid_edge_se2025 |
References
Frequently Asked Questions
What is CVE-2024-54091? +
How severe is CVE-2024-54091? +
What products are affected by CVE-2024-54091? +
How do I check if I'm vulnerable to CVE-2024-54091? +
Related Vulnerabilities
LibreOffice Calc can import tracked changes from a spreadsheet document. A heap buffer overflow existed when a document reused the …
LibreOffice can import presentations in the legacy binary PPT format. A stack buffer overflow existed when importing a colour-replacement record. …
A heap use-after-free existed when importing the blank-width characters of an ODF number format. A position value read from the …
LibreOffice can import drawings in the DXF format used by CAD software. A heap buffer overflow existed when importing a …
The method "sock_recvfrom_into()" of "asyncio.ProacterEventLoop" (Windows only) was missing a boundary check for the data buffer when using nbytes parameter. …
editorconfig-core-c is an EditorConfig core library for use by plugins supporting EditorConfig parsing. Versions up to and including 0.12.10 have …