Out-of-Bounds Read Vulnerability in NX 1980 Series and Solid Edge SE2021 by Siemens
CVE-2021-37203

7.1HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
14 September 2021

Summary

A vulnerability has been identified in the NX 1980 Series and Solid Edge SE2021 products by Siemens. The issue stems from the plmxmlAdapterIFC.dll, which contains an out-of-bounds read flaw when processing user-supplied IFC files. This can lead to a situation where an attacker may read beyond an allocated buffer, potentially resulting in a denial-of-service condition or exposing sensitive information from system memory. Users of the affected versions are urged to update to the latest releases to mitigate these risks.

Affected Version(s)

NX 1980 Series All versions < V1984

Solid Edge SE2021 All versions < SE2021MP8

References

CVSS V3.1

Score:
7.1
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.