First published: Tue Jan 12 2021(Updated: )
A vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Solid Edge SE2020 (All Versions < SE2020MP12), Solid Edge SE2021 (All Versions < SE2021MP2), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications lack proper validation of user-supplied data when parsing PAR files. This can result in an out of bounds write past the memory location that is a read only image address. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-11885)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens JT2Go | <13.1.0.1 | |
Siemens Solid Edge | =se2020 | |
Siemens Solid Edge | =se2020-maintenance_pack1 | |
Siemens Solid Edge | =se2020-maintenance_pack10 | |
Siemens Solid Edge | =se2020-maintenance_pack11 | |
Siemens Solid Edge | =se2020-maintenance_pack2 | |
Siemens Solid Edge | =se2020-maintenance_pack3 | |
Siemens Solid Edge | =se2020-maintenance_pack4 | |
Siemens Solid Edge | =se2020-maintenance_pack5 | |
Siemens Solid Edge | =se2020-maintenance_pack6 | |
Siemens Solid Edge | =se2020-maintenance_pack7 | |
Siemens Solid Edge | =se2020-maintenance_pack8 | |
Siemens Solid Edge | =se2020-maintenance_pack9 | |
Siemens Solid Edge | =se2021 | |
Siemens Solid Edge | =se2021-maintenance_pack1 | |
Siemens Teamcenter Visualization | <13.1.0.1 | |
Siemens JT2Go | <13.1.0.1 | 13.1.0.1 |
Siemens Teamcenter Visualization | <13.1.0.1 | 13.1.0.1 |
Siemens Solid Edge Viewer | ||
Siemens JT2Go | ||
Siemens Solid Edge: All versions prior to SE2021MP2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-28383 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer.
To exploit this vulnerability, user interaction is required, where the target must visit a malicious page or open a malicious file.
Siemens Solid Edge Viewer versions up to 13.1.0.1, Siemens JT2Go versions up to 13.1.0.1, Siemens Solid Edge versions se2020, Siemens Solid Edge versions se2020-maintenance_pack1 to se2020-maintenance_pack11, Siemens Solid Edge versions se2021, Siemens Solid Edge versions se2021-maintenance_pack1, and Siemens Teamcenter Visualization versions up to 13.1.0.1 are affected by this vulnerability.
CVE-2020-28383 has a severity keyword of high and a severity value of 7.8.
To fix this vulnerability, it is recommended to update to the latest version of Siemens Solid Edge Viewer, Siemens JT2Go, Siemens Solid Edge, or Siemens Teamcenter Visualization depending on the affected software.