← Back

CVE-2021-44000

nvd nist
Published: Feb 9, 2022Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A vulnerability has been identified in JT2Go (All versions < V13.2.0.7), Solid Edge SE2021 (All versions < SE2021MP9), Solid Edge SE2022 (All versions < SE2022MP1), Teamcenter Visualization V13.1 (All versions < V13.1.0.9), Teamcenter Visualization V13.2 (All versions < V13.2.0.7), Teamcenter Visualization V13.3 (All versions < V13.3.0.1). The plmxmlAdapterSE70.dll contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15053)

Affected (14)

3 products
Jt2go
Solid Edge
Teamcenter Visualization
Configuration A
14 vulnerable
Vulnerable SoftwareAffected Versions
Before 13.2.0.7
Siemens
Version se2021
Version se2021 maintenance_pack1
Version se2021 maintenance_pack2
Version se2021 maintenance_pack3
Version se2021 maintenance_pack4
Version se2021 maintenance_pack5
Version se2021 maintenance_pack6
Version se2021 maintenance_pack7
Version se2021 maintenance_pack8
Version se2022
Siemens
From 13.2.0 to 13.2.0.7
From 13.3.0 to 13.3.0.1
Version 13.1.0

References (4)

Source: productcert@siemens.com
PatchVendor Advisory
Source: productcert@siemens.com
Third Party AdvisoryVDB Entry
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party AdvisoryVDB Entry

Timeline

No history available yet.