CVE-2024-6377: 3ds 3dexperience

Medium severity, CVSS 6.1. EPSS: 0.3% chance of exploitation in the next 30 days.

An URL redirection to untrusted site (open redirect) vulnerability affecting 3DPassport in 3DSwymer from Release 3DEXPERIENCE R2022x through Release 3DEXPERIENCE R2024x allows an attacker to redirect users to an arbitrary website via a crafted URL.

Affected products

  • 3ds 3dexperience: from r2022x, up to and including r2024x

Published 2024-08-20. Last modified 2026-06-17.