ID

VAR-202502-0246


CVE

CVE-2024-53977


TITLE

Siemens ModelSim and Questa Local Code Execution Vulnerabilities

Trust: 0.6

sources: CNVD: CNVD-2025-15335

DESCRIPTION

A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example setup script contained in affected applications allows a specific executable file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch the script from a user-writable directory. ModelSim is an industry-leading hardware description language (HDL) simulation tool developed by Mentor Graphics (now a Siemens company), mainly used for verification and debugging of digital circuit designs. Questa is an intelligent verification solution launched by Siemens, which aims to optimize the integrated circuit (IC) verification process through artificial intelligence (AI) technology, improve production efficiency and meet complex design challenges

Trust: 1.44

sources: NVD: CVE-2024-53977 // CNVD: CNVD-2025-15335

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-15335

AFFECTED PRODUCTS

vendor:siemensmodel:modelsimscope:ltversion:v2025.1

Trust: 0.6

vendor:siemensmodel:questascope:ltversion:v2025.1

Trust: 0.6

sources: CNVD: CNVD-2025-15335

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2024-53977
value: MEDIUM

Trust: 1.0

CNVD: CNVD-2025-15335
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-15335
severity: MEDIUM
baseScore: 6.0
vectorString: AV:L/AC:H/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 1.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

productcert@siemens.com: CVE-2024-53977
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: LOW
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.9
version: 3.1

Trust: 1.0

sources: CNVD: CNVD-2025-15335 // NVD: CVE-2024-53977

PROBLEMTYPE DATA

problemtype:CWE-427

Trust: 1.0

sources: NVD: CVE-2024-53977

PATCH

title:Patch for Siemens ModelSim and Questa Local Code Execution Vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/706281

Trust: 0.6

sources: CNVD: CNVD-2025-15335

EXTERNAL IDS

db:NVDid:CVE-2024-53977

Trust: 1.6

db:SIEMENSid:SSA-637914

Trust: 1.6

db:CNVDid:CNVD-2025-15335

Trust: 0.6

sources: CNVD: CNVD-2025-15335 // NVD: CVE-2024-53977

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-637914.html

Trust: 1.6

sources: CNVD: CNVD-2025-15335 // NVD: CVE-2024-53977

SOURCES

db:CNVDid:CNVD-2025-15335
db:NVDid:CVE-2024-53977

LAST UPDATE DATE

2025-07-10T23:02:35.474000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-15335date:2025-07-09T00:00:00
db:NVDid:CVE-2024-53977date:2025-02-11T11:15:15.063

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-15335date:2025-02-11T00:00:00
db:NVDid:CVE-2024-53977date:2025-02-11T11:15:15.063