Out-of-Bounds Write Vulnerability in Solid Edge by Siemens
CVE-2021-31342
8.8HIGH
Summary
The vulnerability in the ugeom2d.dll library present in Solid Edge versions 2020 and 2021 occurs due to insufficient validation of user-supplied data during the parsing of DFT files. An attacker who successfully exploits this flaw could potentially perform an out-of-bounds write, allowing them to execute arbitrary code in the context of the affected process. This can lead to unauthorized actions and compromise the integrity of the system.
Affected Version(s)
Siemens Solid Edge Solid Edge SE2020 – All versions before 2020MP14
Siemens Solid Edge Solid Edge SE2021 – All versions before SE2021MP5
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved