VDB
ICSA-21-035-01
ICSA-21-035-01
PUBLISHED
CVSS 7.800000190734863 HIGH
Successful exploitation of these vulnerabilities could allow arbitrary code execution, the storing of arbitrary scripts into automatic startup folders, and the attacking of products without sufficient UI warning.
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| KeyShot: versions prior to 10.1 | ||
| KeyShot Network Rendering: versions prior to 10.1 | ||
| KeyVR: versions prior to 10.1 | ||
| KeyShot Viewer: versions prior to 10.1 |
Timeline
- Feb 4, 2021 CVE Published
- Mar 9, 2021 CVE Updated
References
- https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2021/icsa-21-035-01.json advisory
- https://www.cisa.gov/news-events/ics-advisories/icsa-21-035-01 advisory
- https://us-cert.cisa.gov/ncas/tips/ST04-014 url
- https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf url
- https://us-cert.cisa.gov/ics/tips/ICS-TIP-12-146-01B url
- https://www.keyshot.com/csirt/ fix
- https://new.siemens.com/global/en/products/services/cert.html#SecurityPublications fix