← Back

CVE-2023-38076

nvd nist
Published: Sep 12, 2023Modified: Nov 21, 2024

JSON object

Loading...
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: productcert@siemens.com (Secondary)

Description

A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.1), Tecnomatix Plant Simulation V2201 (All versions < V2201.0010), Tecnomatix Plant Simulation V2302 (All versions < V2302.0004). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21041)

Affected (7)

3 products
Jt2go
Teamcenter Visualization
Tecnomatix Plant Simulation
Configuration A
7 vulnerable
Vulnerable SoftwareAffected Versions
Before 14.3.0.1
Siemens
From 13.3.0 to 13.4.0.12
From 14.0 to 14.1.0.11
From 14.2 to 14.2.0.6
From 14.3 to 14.3.0.1
Siemens
From 2201.0 to 2201.0010
From 2302.0 to 2302.0004

References (4)

Source: productcert@siemens.com
Vendor Advisory
Source: productcert@siemens.com
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory

Timeline

No history available yet.