Out of Bounds Read Vulnerability in Parasolid and Simcenter Femap Products
CVE-2022-39157

7.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
8 November 2022

Summary

A vulnerability exists within various versions of the Parasolid and Simcenter Femap products, characterized by an out of bounds read issue that occurs when specially crafted X_T files are parsed. This flaw may potentially allow an attacker to execute code in the context of the application process, raising concerns about unauthorized access and manipulation of sensitive data.

Affected Version(s)

Parasolid V34.0 All versions < V34.0.252

Parasolid V34.0 All versions >= V34.0.252 < V34.0.254

Parasolid V34.1 All versions < V34.1.242

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.