CVE-2024-33577
Last modified
CVE-2024-33577 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in Simcenter Femap (All versions < V2406). The affected applications contain a stack overflow vulnerability while parsing specially strings as argument for one of the application binaries. This could allow an attacker to execute code in the context of the current process.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Simcenter Femap | < 2406.0000 |
| Siemens | Simcenter Nastran | >= 2306.0, < 2406.90 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2024-33577?
How severe is CVE-2024-33577?
How do I fix CVE-2024-33577?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2024
- CVE-2024-33571Improper Neutralization of Input During Web Page Generation …7.1
- CVE-2024-33572Missing Authorization vulnerability in POSIMYTH Nexter Block…8.8
- CVE-2024-33573Missing Authorization vulnerability in EPROLO EPROLO Dropshi…4.3
- CVE-2024-33574Missing Authorization vulnerability in appsbd Vitepos.This i…4.3
- CVE-2024-33575Exposure of Sensitive Information to an Unauthorized Actor v…5.3
- CVE-2024-33576Missing Authorization vulnerability in Ollybach WPPizza.This…6.5
- CVE-2024-33578A DLL hijack vulnerability was reported in Lenovo Leyun that…7.8
- CVE-2024-33579A DLL hijack vulnerability was reported in Lenovo Baiying th…7.8
- CVE-2024-3358A vulnerability classified as problematic was found in Sourc…6.1
- CVE-2024-33580A DLL hijack vulnerability was reported in Lenovo Personal C…7.8
- CVE-2024-33581A DLL hijack vulnerability was reported in Lenovo PC Manager…7.8
- CVE-2024-33582A DLL hijack vulnerability was reported in Lenovo Service Fr…7.8
Are you affected by CVE-2024-33577?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
