CVE-2024-41908

HIGH

NX <V2406.3000 - Memory Corruption

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in NX (All versions < V2406.3000). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or execute code in the context of the current process.

References (1)

Core 1

Scores

CVSS v3 7.8
EPSS 0.0019
EPSS Percentile 40.4%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-125
Status published
Products (1)
Siemens/NX < V2406.3000
Published Aug 13, 2024
Tracked Since Feb 18, 2026