Nov. 14, 2023, 6 a.m. |

ZDI: Published Advisories www.zerodayinitiative.com

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Tecnomatix Plant Simulation. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2023-38075.

arbitrary code attackers code code execution cvss exploit file free malicious page parsing rating remote code remote code execution siemens simulation target use-after-free vulnerability zdi

More from www.zerodayinitiative.com / ZDI: Published Advisories

Information Security Engineers

@ D. E. Shaw Research | New York City

Infrastructure Security Engineer

@ Instacart | Canada - Remote (ON, AB or BC Only)

Sr. Information Security Analyst

@ AllianceBernstein | Nashville, Tennessee

Network & Security Engineer

@ Alter Solutions | Brussels, Belgium

Security Engineer – Risk Management Framework (RMF), ACAS, ESS

@ ARA | Raleigh, North Carolina, United States; San Antonio, Texas, United States

Chief Information Security Officer

@ Trainline | London, United Kingdom