CVE-2023-37376
Published: 11 July 2023
Summary
CVE-2023-37376 is a high-severity Type Confusion (CWE-843) vulnerability in Siemens Tecnomatix. Its CVSS base score is 7.8 (High).
Operationally, ranked at the 27.3th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2023-41278
Vulnerability details
A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions < V2201.0008), Tecnomatix Plant Simulation V2302 (All versions < V2302.0002). The affected application contains a type confusion vulnerability while parsing STP files. This could allow an attacker to…
more
execute code in the context of the current process. (ZDI-CAN-21051)
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
No mitigating controls mapped yet. The per-CVE control annotator has not reached this CVE.