CVE-2024-22043: Siemens Parasolid

Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.251), Parasolid V35.1 (All versions < V35.1.170). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted XT files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

Affected products

  • Siemens Parasolid: from 35.0, before 35.0.251 (fixed in 35.0.251); from 35.1, before 35.1.170 (fixed in 35.1.170)

Published 2024-02-13. Last modified 2026-06-17.