First published: Tue Jun 08 2021(Updated: )
A vulnerability has been identified in Simcenter Femap 2020.2 (All versions < V2020.2.MP3), Simcenter Femap 2021.1 (All versions < V2021.1.MP3). The femap.exe application lacks proper validation of user-supplied data when parsing FEMAP files. This could result in an out of bounds write past the end of an allocated structure, a different vulnerability than CVE-2021-27399. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12819)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simcenter Femap | <2020.2 | |
Siemens Simcenter Femap | =2020.2 | |
Siemens Simcenter Femap | =2020.2-maintenance_pack1 | |
Siemens Simcenter Femap | =2020.2-maintenance_pack2 | |
Siemens Simcenter Femap | =2021.1 | |
Siemens Simcenter Femap | =2021.1-maintenance_pack1 | |
Siemens Simcenter Femap | =2021.1-maintenance_pack2 | |
Siemens Simcenter Femap | ||
Siemens Simcenter Femap 2020.2, all versions prior to v2020.2.MP3 | ||
Siemens Simcenter Femap 2021.1, all versions prior to v2021.1.MP3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27387 is a vulnerability in Siemens Simcenter Femap that allows remote attackers to execute arbitrary code on affected installations.
CVE-2021-27387 is exploited when a user visits a malicious page or opens a malicious file, allowing remote attackers to execute arbitrary code.
CVE-2021-27387 has a severity score of 7.8 (High).
CVE-2021-27387 affects Siemens Simcenter Femap version 2020.2 and 2021.1, including maintenance packs 1 and 2.
To fix CVE-2021-27387, users should update to the latest version of Siemens Simcenter Femap.