CVE-2022-39144
A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.161), Parasolid V35.0 (All versions >= V35.0.161 < V35.0.164), Simcenter Femap V2022.1 (All versions < V2022.1.3), Simcenter Femap V2022.2 (All versions < V2022.2.2). The affected application contains an out of bounds write past the end of an allocated buffer while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-17494)
EPSS 0.06% · 19.6th percentile
Risk Scores
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Parasolid V34.1 | All versions < V34.1.242 |
| siemens | simcenter_femap | 2022.2, 2022.1 |
| Siemens | Simcenter Femap V2022.1 | All versions < V2022.1.3 |
| Siemens | Parasolid V34.0 | All versions < V34.0.252 |
| siemens | parasolid | 34.0, 33.1, 34.1 |
| Siemens | Simcenter Femap V2022.2 | * |
| Siemens | Parasolid V33.1 | All versions >= V33.1.262 < V33.1.263, All versions < V33.1.262 |
| Siemens | Parasolid V35.0 | *, All versions < V35.0.161 |
Timeline
- Sep 13, 2022 CVE Published
- Sep 14, 2022 EPSS Score
- Sep 15, 2022 EPSS Score
- Oct 29, 2022 EPSS Score
- Dec 13, 2022 EPSS Score
- Jan 27, 2023 EPSS Score
- Mar 7, 2023 EPSS Score
- Mar 13, 2023 EPSS Score
- Apr 26, 2023 EPSS Score
- Jul 25, 2023 EPSS Score
- Sep 8, 2023 EPSS Score
- Oct 23, 2023 EPSS Score
References
- https://cert-portal.siemens.com/productcert/html/ssa-589975.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-638652.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-459643.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-518824.html advisory
- https://cert-portal.siemens.com/productcert/html/ssa-637483.html advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-518824.pdf url
- https://nvd.nist.gov/vuln/detail/CVE-2022-39144 advisory