Out of Bounds Read Vulnerability in Parasolid and Simcenter Femap Products
CVE-2022-39157
7.8HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 8 November 2022
Summary
A vulnerability exists within various versions of the Parasolid and Simcenter Femap products, characterized by an out of bounds read issue that occurs when specially crafted X_T files are parsed. This flaw may potentially allow an attacker to execute code in the context of the application process, raising concerns about unauthorized access and manipulation of sensitive data.
Affected Version(s)
Parasolid V34.0 All versions < V34.0.252
Parasolid V34.0 All versions >= V34.0.252 < V34.0.254
Parasolid V34.1 All versions < V34.1.242
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved