CVE-2024-23801Active Exploitation(siemens / tecnomatix_plant_simulation)

HIGHCVSS 5.5 · MEDIUM

Exploitation ongoing with high activity in latest observed window (1 mentions)

Immediate actions

  • Patch siemens tecnomatix_plant_simulation systems immediately
  • Assume compromise if assets are exposed
  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft

Recommended action window: Immediate (within 24h)

NVD description

A vulnerability has been identified in Tecnomatix Plant Simulation V2201 (All versions), Tecnomatix Plant Simulation V2302 (All versions < V2302.0007). The affected applications contain a null pointer dereference vulnerability while parsing specially crafted SPP files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.

7.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-476

Priority

HIGH

Exploitation

ACTIVE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • tecnomatix_plant_simulation

Threat summary

  • Active exploitation appears in 1 classified signals
  • Public PoC and exploit tooling are both present
  • Patch or workaround signal is available
  • 1 mentions across 1 observed day

What's happening

  • Active exploitation reported across 1 signal
  • Exploit tool or code specified in 1 signal
  • PoC mentioned or linked in 1 signal
  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 1 signal
  • 1 total mentions across 1 day

Affected systems

Vendors
Products
tecnomatix_plant_simulation

1 version affected across 1 product

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-02-12: 1PoC Mentioned / Linked · 2026-02-12: 1Exploit Tool / Code · 2026-02-12: 1Active Exploitation · 2026-02-12: 1Patch / Workaround · 2026-02-12: 1Technical Details · 2026-02-12: 102-12
Signal classification1 categories
Active Exploitation
1100.0%
Referenced assets1 URL
Full discourse1 post
  • 趣テクノロジー@omomuki_tech
    Active Exploitation

    BeyondTrust社のRemote SupportおよびPrivileged Remote Access製品において、認証なしでリモートからコードを実行される可能性のある深刻な脆弱性(CVE-2024-23801)が報告されています。 この脆弱性は、CVSSスコアで9.8と評価されており、セキュリティレベルは「緊急(Critical)」に分類される非常に危険度の高いものです。 具体的には、特別に細工されたデータをアプライアンスに送信することで、認証を回避して遠隔から任意のコードを実行できてしまう可能性があります。 既にこの脆弱性を悪用するための概念実証(PoC)コードがオンラインで公開されており、実際に攻撃で利用されていることが確認されています。 BeyondTrust社は、この問題に対処するためのセキュリティパッチをリリースしています。 該当する製品を利用している管理者の皆さまは、ただちに最新バージョンへのアップデートを適用することが強く推奨されます。 #BeyondTrust #脆弱性 #サイバーセキュリティ https://www.bleepingcomputer.com/news/security/critical-beyondtrust-rce-flaw-now-exploited-in-attacks-patch-now/

    Post summary

    CVE-2024-23801, a critical RCE flaw in BeyondTrust products, has an online PoC and confirmed active attacks, prompting a patch release.

    0000052
    240 followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appsiemenstecnomatix_plant_simulation---
Appsiemenstecnomatix_plant_simulation2201.0--

Explore more