Buffer Overflow Vulnerability in JT2Go, Solid Edge, and Teamcenter Visualization
CVE-2021-34327

7.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
13 July 2021

Summary

A vulnerability exists in the plmxmlAdapterSE70.dll library used by JT2Go, Solid Edge, and Teamcenter Visualization. This issue arises from inadequate validation of user-supplied data during ASM file parsing. Such flaws can allow an attacker to perform an out-of-bounds write operation, which could lead to code execution within the context of the current process. Organizations using affected versions should prioritize upgrading to mitigate potential risks associated with this vulnerability.

Affected Version(s)

JT2Go All versions < V13.2

Solid Edge SE2021 All Versions < SE2021MP5

Teamcenter Visualization All versions < V13.2

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.