CVSS 3.1 Score 7.8 of 10 (high)


Published Feb 13, 2024
CWE ID 125


CVE-2024-24923 is a vulnerability identified in Simcenter Femap software versions prior to V2401.0000 and V2306.0001. The vulnerability allows for an out-of-bounds read past the end of an allocated structure when parsing specially crafted Catia MODEL files, potentially enabling an attacker to execute code within the current process. The risk score for this vulnerability is 25, indicating a high severity level. The base score is 7.8, with confidentiality and integrity impacts rated as high. The attacker does not require any privileges, but user interaction is required, and the attack vector is local. To remediate this vulnerability, users should update their Simcenter Femap software to versions V2401.0000 or V2306.0001 or later. Failure to address this vulnerability could lead to unauthorized code execution and potential compromise of sensitive data within an organization's systems using the affected software versions

Explore Beyond the CVE Basics with Recorded Future's Vulnerability Intelligence

Note: This is just a basic overview providing quick insights into CVE-2024-24923 information. Gain full access to comprehensive CVE data, risk scores, prioritization, and mitigation data through Recorded Future's Vulnerability Intelligence:
  • Prioritize with Risk-Based Scoring
  • Explore the Extensive Vulnerability Database
  • Receive Early Alerts on Emerging CVEs
  • Focus on Critical Exploitable Vulnerabilities
  • Streamline Remediation with Integration Options