Out of Bounds Write Vulnerability in Solid Edge by Siemens
CVE-2020-28382
7.8HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 12 January 2021
Summary
A vulnerability has been discovered in Solid Edge applications that stems from insufficient validation of user-supplied data during the parsing of PAR files. This deficiency can lead to an out-of-bounds write, which occurs when data is written past the memory allocated for a specific structure. Consequently, an attacker could exploit this vulnerability to execute arbitrary code within the current process context, potentially resulting in unauthorized actions or access to sensitive information.
Affected Version(s)
Solid Edge SE2020 All Versions < SE2020MP12
Solid Edge SE2021 All Versions < SE2021MP2
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved