VDB
SSA-715184
SSA-715184
PUBLISHED
CVSS 5.599999904632568 MEDIUM
Affected applications lack proper validation of user-supplied data when parsing DFT files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12049)
Risk Scores
CVSS 3.1
5.599999904632568
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:L/E:P/RL:O/RC:C
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Solid Edge SE2021 | |
| Siemens | Solid Edge SE2020 |
Timeline
- Mar 9, 2021 CVE Published
- Apr 13, 2021 CVE Updated
References
- https://cert-portal.siemens.com/productcert/csaf/ssa-715184.json advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-715184.pdf advisory
- https://cert-portal.siemens.com/productcert/txt/ssa-715184.txt advisory
- https://cert-portal.siemens.com/productcert/mitre/CVE-2020-28385.json advisory
- https://cert-portal.siemens.com/productcert/mitre/CVE-2020-28387.json advisory
- https://cert-portal.siemens.com/productcert/mitre/CVE-2021-27380.json advisory
- https://cert-portal.siemens.com/productcert/mitre/CVE-2021-27381.json advisory