A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vsimk.exe in affected applications allows a specific tcl file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch vsimk.exe from a user-writable directory.
Metrics
Affected Vendors & Products
References
History
Tue, 08 Oct 2024 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Siemens
Siemens modelsim Siemens questa |
|
CPEs | cpe:2.3:a:siemens:modelsim:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:questa:*:*:*:*:*:*:*:* |
|
Vendors & Products |
Siemens
Siemens modelsim Siemens questa |
|
Metrics |
ssvc
|
Tue, 08 Oct 2024 09:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A vulnerability has been identified in ModelSim (All versions < V2024.3), Questa (All versions < V2024.3). vsimk.exe in affected applications allows a specific tcl file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch vsimk.exe from a user-writable directory. | |
Weaknesses | CWE-427 | |
References |
| |
Metrics |
cvssV3_1
|
MITRE
Status: PUBLISHED
Assigner: siemens
Published: 2024-10-08T08:40:49.065Z
Updated: 2024-10-08T16:49:55.857Z
Reserved: 2024-09-20T15:14:29.689Z
Link: CVE-2024-47196
Vulnrichment
Updated: 2024-10-08T16:49:48.286Z
NVD
Status : Analyzed
Published: 2024-10-08T09:15:17.563
Modified: 2024-10-16T18:07:38.850
Link: CVE-2024-47196
Redhat
No data.