Siemens Teamcenter Visualization and Tecnomatix Plant Simulation Memory Corruption Vulnerability Allowing Code Execution

Vulnerability

A memory corruption vulnerability has been identified in Siemens Teamcenter Visualization versions 14.3 (prior to 14.3.0.13), 2312 (prior to 2312.0009), 2406 (prior to 2406.0007), and 2412 (prior to 2412.0002), as well as in Tecnomatix Plant Simulation versions 2302 (prior to 2302.0021) and 2404 (prior to 2404.0010). The vulnerability arises while the application parses specially crafted WRL files, potentially allowing an attacker to execute code in the context of the current process.

Impact

Exploitation of this vulnerability could lead to memory corruption, allowing for arbitrary code execution in the context of the current process.

Remediation

Users are advised to update to the latest versions of the affected products. Specific update instructions can be found on the Siemens Support website. Additionally, as a general security measure, Siemens recommends not opening untrusted WRL files in the affected applications.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.4
impact
7.5
exploitability
4.4
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.