CVSS 3.1 Score 7.8 of 10 (high)


Published Feb 13, 2024
CWE ID 125


CVE-2024-24923 is a vulnerability identified in Simcenter Femap software versions prior to V2401.0000 and V2306.0001. The vulnerability allows for an out-of-bounds read past the end of an allocated structure when parsing specially crafted Catia MODEL files, potentially enabling an attacker to execute code within the current process. The risk score for this vulnerability is 25, indicating a high severity level. The base score is 7.8, with confidentiality and integrity impacts rated as high. The attacker does not require any privileges, but user interaction is required, and the attack vector is local. To remediate this vulnerability, users should update their Simcenter Femap software to versions V2401.0000 or V2306.0001 or later. Failure to address this vulnerability could lead to unauthorized code execution and potential compromise of sensitive data within an organization's systems using the affected software versions

Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.


Prioritize, Pinpoint, and Act to Prevent Vulnerability Exploits with Recorded Future

Note: This is just a basic overview providing quick insights into CVE-2024-24923 information. Gain full access to comprehensive CVE data, third party vulnerabilities, compromised credentials and more with Recorded Future
  • Gain complete coverage of your cyber, third party, and physical attack surface
  • Proactively mitigate threats before they turn into costly attacks
  • Make fast, effective, data-driven decisions