Out of Bounds Write Vulnerability in Solid Edge SE2023 from Siemens
CVE-2023-39419

7.8HIGH

Key Information:

Vendor
Siemens
Vendor
CVE Published:
8 August 2023

Summary

An out of bounds write vulnerability has been discovered in Solid Edge SE2023, where specially crafted DFT files can cause a write past the end of an allocated structure. This flaw can result in unauthorized code execution within the context of the current process, potentially compromising system integrity and user data.

Affected Version(s)

Solid Edge SE2023 All versions < V223.0 Update 7

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.