Out of Bounds Read in JT2Go and Teamcenter Visualization Software
CVE-2023-38682
7.8HIGH
Key Information:
- Vendor
- Siemens
- Status
- Vendor
- CVE Published:
- 8 August 2023
Summary
A vulnerability exists in the JT2Go and Teamcenter Visualization applications that allows for an out-of-bounds read during the processing of specially crafted TIFF files. This flaw can lead to the execution of code in the context of the current process, potentially allowing malicious actors to exploit the software. Affected versions must be updated to mitigate this risk.
Affected Version(s)
JT2Go All versions < V14.2.0.5
Teamcenter Visualization V13.2 All versions < V13.2.0.14
Teamcenter Visualization V14.1 All versions < V14.1.0.10
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved