Out-of-Bounds Write Vulnerability in Solid Edge by Siemens
CVE-2021-31343
8.8HIGH
Summary
The jutil.dll library in all versions of Solid Edge SE2020 prior to 2020MP14 and in all versions of Solid Edge SE2021 prior to SE2021MP5 is vulnerable due to insufficient validation of user-supplied data during the parsing of DFT files. This flaw may allow an attacker to exploit the vulnerability to perform an out-of-bounds write operation, leading to potential arbitrary code execution in the context of the affected process. This risk underscores the importance of updating to secure versions to mitigate potential exploitation.
Affected Version(s)
Siemens Solid Edge Solid Edge SE2020 – All versions before 2020MP14
Siemens Solid Edge Solid Edge SE2021 – All versions before SE2021MP5
References
CVSS V3.1
Score:
8.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved