Information Disclosure Vulnerability in Bentley View by Bentley Systems
CVE-2021-46654
3.3LOW
What is CVE-2021-46654?
A vulnerability exists in Bentley View 10.15.0.75 that enables remote attackers to exploit sensitive information disclosure. The flaw resides in the parsing mechanism of DGN files, where improper validation of user-supplied data can lead to a read past the allocated buffer. Exploitation requires user interaction, as the target must visit a malicious webpage or open a compromised file. Furthermore, this vulnerability may potentially be leveraged alongside other weaknesses to execute arbitrary code within the context of the affected process.
Affected Version(s)
View 10.15.0.75