Memory Corruption Vulnerability in Siemens JT2Go and Teamcenter Visualization Products
CVE-2021-44018
7.8HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 9 February 2022
Summary
A vulnerability exists in the plmxmlAdapterSE70.dll library utilized by Siemens JT2Go, Solid Edge, and Teamcenter Visualization products. Specifically, the flaw arises when the library processes specially crafted PAR files, leading to a memory corruption condition. This could allow an attacker to manipulate the affected process, potentially enabling arbitrary code execution within the same context. Users are advised to update their software to the latest versions to mitigate the risks associated with this vulnerability.
Affected Version(s)
JT2Go All versions < V13.2.0.7
Solid Edge SE2021 All versions < SE2021MP9
Solid Edge SE2022 All versions < SE2022MP1
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved