CVE-2024-31980: Siemens Parasolid
High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.
A vulnerability has been identified in Parasolid V35.1 (All versions < V35.1.256), Parasolid V36.0 (All versions < V36.0.210), Parasolid V36.1 (All versions < V36.1.185). The affected application contains an out of bounds write past the end of an allocated buffer while parsing a specially crafted X_T part file. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-23468)
Affected products
- Siemens Parasolid: from 35.1, before 35.1.256 (fixed in 35.1.256); from 36.0, before 36.0.210 (fixed in 36.0.210); from 36.1, before 36.1.185 (fixed in 36.1.185)
Published 2024-05-14. Last modified 2026-06-17.