ID

VAR-202502-0246


CVE

CVE-2024-53977


TITLE

Siemens'  ModelSim Simulation  and  Questa Simulation  Vulnerability regarding uncontrolled search path elements in

Trust: 0.8

sources: JVNDB: JVNDB-2024-028281

DESCRIPTION

A vulnerability has been identified in ModelSim (All versions < V2025.1), Questa (All versions < V2025.1). An example setup script contained in affected applications allows a specific executable file to be loaded from the current working directory. This could allow an authenticated local attacker to inject arbitrary code and escalate privileges in installations where administrators or processes with elevated privileges launch the script from a user-writable directory. Siemens' ModelSim Simulation and Questa Simulation Exists in a vulnerability in an element of an uncontrolled search path.Information is obtained, information is tampered with, and service operation is interrupted. (DoS) It may be in a state. ModelSim is an industry-leading hardware description language (HDL) simulation tool developed by Mentor Graphics (now a Siemens company), mainly used for verification and debugging of digital circuit designs. Questa is an intelligent verification solution launched by Siemens, which aims to optimize the integrated circuit (IC) verification process through artificial intelligence (AI) technology, improve production efficiency and meet complex design challenges

Trust: 2.16

sources: NVD: CVE-2024-53977 // JVNDB: JVNDB-2024-028281 // CNVD: CNVD-2025-15335

IOT TAXONOMY

category:['IoT']sub_category: -

Trust: 0.6

sources: CNVD: CNVD-2025-15335

AFFECTED PRODUCTS

vendor:siemensmodel:modelsimscope:ltversion:2025.1

Trust: 1.0

vendor:siemensmodel:questascope:ltversion:2025.1

Trust: 1.0

vendor:シーメンスmodel:modelsim simulationscope: - version: -

Trust: 0.8

vendor:シーメンスmodel:questa simulationscope: - version: -

Trust: 0.8

vendor:siemensmodel:modelsimscope:ltversion:v2025.1

Trust: 0.6

vendor:siemensmodel:questascope:ltversion:v2025.1

Trust: 0.6

sources: CNVD: CNVD-2025-15335 // JVNDB: JVNDB-2024-028281 // NVD: CVE-2024-53977

CVSS

SEVERITY

CVSSV2

CVSSV3

productcert@siemens.com: CVE-2024-53977
value: MEDIUM

Trust: 1.0

nvd@nist.gov: CVE-2024-53977
value: HIGH

Trust: 1.0

NVD: CVE-2024-53977
value: HIGH

Trust: 0.8

CNVD: CNVD-2025-15335
value: MEDIUM

Trust: 0.6

CNVD: CNVD-2025-15335
severity: MEDIUM
baseScore: 6.0
vectorString: AV:L/AC:H/AU:S/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: HIGH
authentication: SINGLE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 1.5
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.6

productcert@siemens.com: CVE-2024-53977
baseSeverity: MEDIUM
baseScore: 6.7
vectorString: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: HIGH
privilegesRequired: LOW
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 0.8
impactScore: 5.9
version: 3.1

Trust: 1.0

nvd@nist.gov: CVE-2024-53977
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 1.0

NVD: CVE-2024-53977
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: NONE
impactScore: NONE
version: 3.0

Trust: 0.8

sources: CNVD: CNVD-2025-15335 // JVNDB: JVNDB-2024-028281 // NVD: CVE-2024-53977 // NVD: CVE-2024-53977

PROBLEMTYPE DATA

problemtype:CWE-427

Trust: 1.0

problemtype:Uncontrolled search path elements (CWE-427) [ others ]

Trust: 0.8

sources: JVNDB: JVNDB-2024-028281 // NVD: CVE-2024-53977

PATCH

title:Patch for Siemens ModelSim and Questa Local Code Execution Vulnerabilitiesurl:https://www.cnvd.org.cn/patchInfo/show/706281

Trust: 0.6

sources: CNVD: CNVD-2025-15335

EXTERNAL IDS

db:NVDid:CVE-2024-53977

Trust: 3.2

db:SIEMENSid:SSA-637914

Trust: 2.4

db:ICS CERTid:ICSA-25-044-10

Trust: 0.8

db:JVNid:JVNVU95962757

Trust: 0.8

db:JVNDBid:JVNDB-2024-028281

Trust: 0.8

db:CNVDid:CNVD-2025-15335

Trust: 0.6

sources: CNVD: CNVD-2025-15335 // JVNDB: JVNDB-2024-028281 // NVD: CVE-2024-53977

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-637914.html

Trust: 2.4

url:https://jvn.jp/vu/jvnvu95962757/

Trust: 0.8

url:https://nvd.nist.gov/vuln/detail/cve-2024-53977

Trust: 0.8

url:https://www.cisa.gov/news-events/ics-advisories/icsa-25-044-10

Trust: 0.8

sources: CNVD: CNVD-2025-15335 // JVNDB: JVNDB-2024-028281 // NVD: CVE-2024-53977

SOURCES

db:CNVDid:CNVD-2025-15335
db:JVNDBid:JVNDB-2024-028281
db:NVDid:CVE-2024-53977

LAST UPDATE DATE

2025-10-03T21:26:58.834000+00:00


SOURCES UPDATE DATE

db:CNVDid:CNVD-2025-15335date:2025-07-09T00:00:00
db:JVNDBid:JVNDB-2024-028281date:2025-10-01T08:11:00
db:NVDid:CVE-2024-53977date:2025-09-25T13:39:30.720

SOURCES RELEASE DATE

db:CNVDid:CNVD-2025-15335date:2025-02-11T00:00:00
db:JVNDBid:JVNDB-2024-028281date:2025-10-01T00:00:00
db:NVDid:CVE-2024-53977date:2025-02-11T11:15:15.063