Memory Corruption Vulnerability in Siemens JT2Go and Teamcenter Visualization Products
CVE-2021-44018

7.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
9 February 2022

Summary

A vulnerability exists in the plmxmlAdapterSE70.dll library utilized by Siemens JT2Go, Solid Edge, and Teamcenter Visualization products. Specifically, the flaw arises when the library processes specially crafted PAR files, leading to a memory corruption condition. This could allow an attacker to manipulate the affected process, potentially enabling arbitrary code execution within the same context. Users are advised to update their software to the latest versions to mitigate the risks associated with this vulnerability.

Affected Version(s)

JT2Go All versions < V13.2.0.7

Solid Edge SE2021 All versions < SE2021MP9

Solid Edge SE2022 All versions < SE2022MP1

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.