← Back

CVE-2022-41851

nvd nist
Published: Oct 11, 2022Modified: May 20, 2025

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A vulnerability has been identified in JTTK (All versions < V11.1.1.0), Simcenter Femap V2022.1 (All versions < V2022.1.3), Simcenter Femap V2022.2 (All versions < V2022.2.2). The JTTK library is vulnerable to an uninitialized pointer reference vulnerability while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-16973)

Affected (3)

2 products
Jt Open Toolkit
Simcenter Femap
Configuration A
3 vulnerable
Vulnerable SoftwareAffected Versions
Before 11.1.1.0
Siemens
From 2022.1.0 to 2022.1.3
From 2022.2.0 to 2022.2.2

References (2)

Source: productcert@siemens.com
PatchVendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.