CVE-2021-44002
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
A vulnerability has been identified in JT Open (All versions < V11.1.1.0), JT Utilities (All versions < V13.1.1.0), Solid Edge (All versions < V2023). The Jt1001.dll contains an out of bounds write past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15058, ZDI-CAN-19076, ZDI-CAN-19077)
Affected (5)
Products: Siemens: Jt2go, Jt Open Toolkit, Jt Utilities, Solid Edge, Teamcenter Visualization
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| Before 13.2.0.5 | |
| Before 11.1.1.0 | |
| Before 13.1.1.0 | |
| Before se2023 | |
| Before 13.2.0.5 |
References (4)
Source: productcert@siemens.com
PatchVendor Advisory
Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.