CVE-2020-26997: Buffer Overflow
A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2020 (All versions < SE2020MP14), Solid Edge SE2021 (All Versions < SE2021MP4). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could lead to pointer dereferences of a value obtained from untrusted source. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11919)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2020-26997?
The severity of CVE-2020-26997 is high with a value of 7.8.
What is affected by CVE-2020-26997?
Solid Edge SE2020 (all versions prior to SE2020MP13), Solid Edge SE2020 (all versions prior to SE2020MP14), and Solid Edge SE2021 (all versions prior to SE2021MP4) are affected by CVE-2020-26997.
What is the vulnerability description of CVE-2020-26997?
CVE-2020-26997 is a vulnerability found in Solid Edge SE2020 and SE2021 that is caused by the lack of proper validation of user-supplied data when parsing PAR files, which can lead to pointer derangement.
How can the CVE-2020-26997 vulnerability be exploited?
The CVE-2020-26997 vulnerability can be exploited by supplying malicious input in PAR files during the parsing process.
Are there any references for CVE-2020-26997?
Yes, you can refer to the following documents for more information on CVE-2020-26997: [Link 1](https://cert-portal.siemens.com/productcert/pdf/ssa-574442.pdf) and [Link 2](https://us-cert.cisa.gov/ics/advisories/icsa-21-103-06).