Null Pointer Dereference Vulnerability in JT2Go and Teamcenter Visualization by Siemens
CVE-2023-33121
5.5MEDIUM
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 13 June 2023
Summary
A null pointer dereference vulnerability has been discovered in JT2Go and various versions of Teamcenter Visualization from Siemens. This vulnerability occurs when the applications attempt to parse specially crafted CGM files. If successfully exploited, an attacker could crash the application, leading to a denial of service condition, effectively disrupting normal operations.
Affected Version(s)
JT2Go All versions < V14.2.0.3
Teamcenter Visualization V13.2 All versions < V13.2.0.13
Teamcenter Visualization V13.3 All versions < V13.3.0.10
References
CVSS V3.1
Score:
5.5
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved