A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example setup script contained in affected applications allows a specific executable file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch the script from a user-writable directory.
Metrics
Affected Vendors & Products
References
History
Thu, 25 Sep 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| CPEs | cpe:2.3:a:siemens:modelsim:*:*:*:*:*:*:*:* cpe:2.3:a:siemens:questa:*:*:*:*:*:*:*:* |
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 11 Feb 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 11 Feb 2025 10:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example setup script contained in affected applications allows a specific executable file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch the script from a user-writable directory. | |
| Weaknesses | CWE-427 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: siemens
Published: 2025-02-11T10:28:56.961Z
Updated: 2025-02-11T14:33:10.686Z
Reserved: 2024-11-25T20:29:43.782Z
Link: CVE-2024-53977
Updated: 2025-02-11T14:33:05.513Z
Status : Analyzed
Published: 2025-02-11T11:15:15.063
Modified: 2025-09-25T13:39:30.720
Link: CVE-2024-53977
No data.