← Back

CVE-2023-28830

nvd nist
Published: Aug 8, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD

Description

A vulnerability has been identified in JT2Go (All versions < V14.2.0.5), Solid Edge SE2022 (All versions < V222.0 Update 13), Solid Edge SE2023 (All versions < V223.0 Update 4), Teamcenter Visualization V13.2 (All versions < V13.2.0.15), Teamcenter Visualization V13.3 (All versions < V13.3.0.11), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.5). The affected application contains a use-after-free vulnerability that could be triggered while parsing specially crafted ASM file. An attacker could leverage this vulnerability to execute code in the context of the current process.

Affected (21)

4 products
Jt2go
Teamcenter Visualization
Solid Edge Se2022
Solid Edge Se2023
Configuration A
5 vulnerable
Vulnerable SoftwareAffected Versions
Before 14.2.0.5
Siemens
From 13.2.0 to 13.2.0.15
From 13.3.0 to 13.3.0.11
From 14.1 to 14.1.0.11
From 14.2 to 14.2.0.5
Configuration B
16 vulnerable
Vulnerable SoftwareAffected Versions
Siemens
All versions
Version maintenance_pack_10
Version maintenance_pack_11
Version maintenance_pack_12
Version maintenance_pack_1
Version maintenance_pack_2
Version maintenance_pack_3
Version maintenance_pack_4
Version maintenance_pack_5
Version maintenance_pack_7
Version maintenance_pack_8
Version maintenance_pack_9
Siemens
All versions
Version update_0001
Version update_0002
Version update_0003

References (2)

Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.