Out-of-Bounds Write Vulnerability in Solid Edge SE2023 by Siemens
CVE-2023-49128
7.8HIGH
Summary
A vulnerability has been detected in Solid Edge SE2023 that involves an out-of-bounds write resulting from improper handling of specially crafted PAR files. This flaw arises when the application processes data beyond the limits of allocated buffers, which can potentially lead to unauthorized code execution within the context of the affected application. Users of all versions earlier than V223.0 Update 10 should consider applying the latest updates to mitigate this security risk.
Affected Version(s)
Solid Edge SE2023 All versions < V223.0 Update 10
References
CVSS V3.1
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved