Out of Bounds Read Vulnerability in JT2Go and Teamcenter Visualization by Siemens
CVE-2022-41281
7.8HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 13 December 2022
Summary
An out of bounds read vulnerability exists in the CGM_NIST_Loader.dll of the JT2Go and Teamcenter Visualization products. This issue affects multiple versions of the software and allows an attacker to exploit the vulnerability by crafting a malicious CGM file. When the vulnerable software attempts to parse this file, it may lead to read access violations, allowing the attacker to execute arbitrary code within the context of the affected application. It is crucial for users to update their software to the latest versions to mitigate potential security risks.
Affected Version(s)
JT2Go All versions < V14.1.0.6
Teamcenter Visualization V13.2 All versions < V13.2.0.12
Teamcenter Visualization V13.3 All versions < V13.3.0.8
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved