Out of Bounds Read Vulnerability in Parasolid and Solid Edge Products
CVE-2023-25140
7.8HIGH
Key Information:
- Vendor
- Siemens
- Vendor
- CVE Published:
- 14 February 2023
Summary
A significant vulnerability has been found in multiple versions of Parasolid and Solid Edge products. This issue arises from an out of bounds read, which occurs during the parsing of specially crafted PAR files. The flaw allows attackers to exploit the vulnerability, potentially executing arbitrary code within the context of the affected process. Users of the impacted versions are strongly encouraged to apply the necessary updates to safeguard their systems against potential exploitation.
Affected Version(s)
Parasolid V34.0 All versions < V34.0.254
Parasolid V34.1 All versions < V34.1.242
Parasolid V35.0 All versions < V35.0.170
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved