Buffer Overflow Vulnerability in JT2Go, Solid Edge, and Teamcenter Visualization
CVE-2021-34327
7.8HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 13 July 2021
Summary
A vulnerability exists in the plmxmlAdapterSE70.dll library used by JT2Go, Solid Edge, and Teamcenter Visualization. This issue arises from inadequate validation of user-supplied data during ASM file parsing. Such flaws can allow an attacker to perform an out-of-bounds write operation, which could lead to code execution within the context of the current process. Organizations using affected versions should prioritize upgrading to mitigate potential risks associated with this vulnerability.
Affected Version(s)
JT2Go All versions < V13.2
Solid Edge SE2021 All Versions < SE2021MP5
Teamcenter Visualization All versions < V13.2
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved