Security readout for executives and security teams
Plain-English summary
This affects Siemens Solid Edge workstations. A malicious PAR file could make the application run attacker-controlled code with the user’s privileges. The risk is highest where engineers open externally supplied CAD files.
Executive priority
Prioritize patching affected engineering systems, particularly teams exchanging CAD files externally. This is not described as remotely exploitable over the network, but successful exploitation could compromise sensitive designs and workstation integrity.
Technical view
Solid Edge SE2022 before V222.0MP12 and SE2023 before V223.0Update2 have uninitialized pointer access while parsing crafted PAR files. CVSS 3.1 is 7.8, requiring local user interaction, with high confidentiality, integrity, and availability impact.
Likely exposure
Exposure is limited to environments running affected Solid Edge SE2022 or SE2023 versions, especially endpoints that receive PAR files from vendors, customers, or shared engineering workflows.
Exploitation context
The provided sources do not show known active exploitation, and CISA KEV status is false. Exploitation requires a user or workflow to open or process a malicious PAR file.
Researcher notes
The issue maps to CWE-824 and is triggered during crafted PAR file parsing. The public bundle confirms official remediation levels but does not include exploit details, public exploitation evidence, or deeper root-cause analysis.
Mitigation direction
- Upgrade Solid Edge SE2022 to V222.0MP12 or later.
- Upgrade Solid Edge SE2023 to V223.0Update2 or later.
- Follow Siemens advisory SSA-491245 for vendor-specific guidance.
- Restrict opening PAR files from untrusted or unauthenticated sources.
- Apply endpoint controls to engineering workstations handling external CAD files.
Validation and detection
- Inventory installed Solid Edge SE2022 and SE2023 versions.
- Compare versions against V222.0MP12 and V223.0Update2 thresholds.
- Confirm patched builds are deployed on engineering workstations.
- Review workflows that ingest external PAR files.
- Check security tooling coverage for suspicious Solid Edge process behavior.
Public sources used
Generated from the cited source records. This long-tail analysis has not been individually reviewed by a named human.
Conservative CVE-to-ATT&CK context
These mappings and lookup hints may be relevant to the vulnerability behavior, CWE, affected product, or exposure path. Glexia-inferred context is not an official MITRE, ATT&CK, CWE, or CVE Program mapping.
ATT&CK lookup starting points
Use these exact CWE pages and searches to review the Glexia ATT&CK library from this CVE's weakness and description context.
CWE-824: Exact CWE lookup
Use the exact CWE identifier as the starting point before reviewing related ATT&CK behavior. Open the exact CWE lookup page first, then review the ATT&CK searches from that MITRE weakness context. This is a Glexia lookup hint, not an official ATT&CK mapping.
Open ATT&CK lookupCVE-2023-24563 mapping review
Open the CVE-to-ATT&CK bridge for reviewed, inferred, or future official mappings tied to this CVE.
Open ATT&CK lookup- Severity
- High
- CVSS
- 7.8 (3.1)
- Known Exploited
- No
- Published
Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CNA and ADP enrichment extracted from CVE v5
These fields come from the CVE record and ADP containers, not from Glexia's Take. They preserve time-varying source decisions such as CISA SSVC, KEV status, CVSS metrics, and provider references.
CVSS vector scores
1 official scoreWe collect every scored CVSS vector available in the official CNA and ADP containers. When more than one version is present, the table keeps the source vectors side by side instead of collapsing them into the highest score.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C1.85.9Primary CVE scoreVulnerability scoring details
Base CVSS 3.1 score
7.8HighVector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
Source materials
- CVE List V5 sourceCVE List V5
- https://cert-portal.siemens.com/productcert/pdf/ssa-491245.pdfCVE reference
Products and packages named in the record
CWE details
CWE links open Glexia weakness intelligence pages with official CWE context, developer remediation guidance, and related CVE mappings.
Access of Uninitialized Pointer
Access of Uninitialized Pointer represents a recurring weakness pattern that can create exploitable paths when design, validation, or implementation controls are missing.
