← Vulnerability feed

Vulnerability record · CVE-2024-26276 · published 9 April 2024

CVE-2024-26276: Siemens jt2go allocation without limits vulnerability

Siemens · Jt2go

A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.9), Teamcenter Visualization V2312 (All versions < V2312.0004). The affected application contains a stack exhaustion vulnerability while parsing a specially crafted X_T file. This could allow an attacker to cause denial of service condition.

4.8 CVSS 4.0 Medium EPSS 0.22% · top 88.1% CWE-770 · Allocation without limits
4.8CVSS 4.0 base score
0.22%EPSS exploitation probability, 30 days
NoNot in CISA KEV
3Affected product versions listed by NVD
4References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in JT2Go (All versions < V2312.0004), Parasolid V35.1 (All versions < V35.1.254), Parasolid V36.0 (All versions < V36.0.207), Parasolid V36.1 (All versions < V36.1.147), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.9), Teamcenter Visualization V2312 (All versions < V2312.0004). The affected application contains a stack exhaustion vulnerability while parsing a specially crafted X_T file. This could allow an attacker to cause denial of service condition.

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-26276 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-40355Siemens teamcenter visualization insecure direct object reference vulnerabilityA vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (Al…EPSS 0.80%8.8CVE-2020-26987Siemens jt2go heap-based buffer overflow vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack …EPSS 4.3%8.8CVE-2020-26988Siemens jt2go out-of-bounds write vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack …EPSS 3.1%8.8CVE-2020-26990Siemens jt2go type confusion vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications l…EPSS 3.9%8.8CVE-2020-26991Siemens jt2go null pointer dereference vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected applications l…EPSS 4.0%8.8CVE-2020-26994Siemens jt2go heap-based buffer overflow vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack …EPSS 2.1%8.8CVE-2020-26995Siemens jt2go out-of-bounds write vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack …EPSS 3.5%8.8CVE-2020-26996Siemens jt2go out-of-bounds read vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack …EPSS 3.1%

Source: NIST National Vulnerability Database (record CVE-2024-26276), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.