First published: Mon Jan 18 2021(Updated: )
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Conversion issue exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart).
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Opendesign Drawings Software Development Kit | <2021.11 | |
Siemens COMOS | <10.4.1 | |
Siemens JT2Go | <13.1.0.1 | |
Siemens Teamcenter Visualization | <13.1.0.1 | |
Siemens JT2Go | ||
Siemens JT2Go | <13.1.0.1 | 13.1.0.1 |
Siemens Teamcenter Visualization | <13.1.0.1 | 13.1.0.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-25175.
The severity of CVE-2021-25175 is high with a CVSS score of 7.8.
This vulnerability can be exploited by remote attackers through user interaction, such as visiting a malicious page or opening a malicious file.
Siemens JT2Go, Opendesign Drawings Software Development Kit, Siemens COMOS, and Siemens Teamcenter Visualization are affected by this vulnerability.
To fix this vulnerability, it is recommended to apply the latest updates and patches provided by Siemens or follow the mitigation steps outlined in the advisory.