First published: Tue Jun 08 2021(Updated: )
A vulnerability has been identified in Simcenter Femap 2020.2 (All versions < V2020.2.MP3), Simcenter Femap 2021.1 (All versions < V2021.1.MP3). The femap.exe application lacks proper validation of user-supplied data when parsing FEMAP files. This could result in an out of bounds write past the end of an allocated structure, a different vulnerability than CVE-2021-27387. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12820)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simcenter Femap | <2020.2 | |
Siemens Simcenter Femap | =2020.2 | |
Siemens Simcenter Femap | =2020.2-maintenance_pack1 | |
Siemens Simcenter Femap | =2020.2-maintenance_pack2 | |
Siemens Simcenter Femap | =2021.1 | |
Siemens Simcenter Femap | =2021.1-maintenance_pack1 | |
Siemens Simcenter Femap | =2021.1-maintenance_pack2 | |
Siemens Simcenter Femap | ||
Siemens Simcenter Femap 2020.2, all versions prior to v2020.2.MP3 | ||
Siemens Simcenter Femap 2021.1, all versions prior to v2021.1.MP3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-27399 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Siemens Simcenter Femap.
The CVE-2021-27399 vulnerability can be exploited by visiting a malicious page or opening a malicious file.
Simcenter Femap versions 2020.2, 2020.2-maintenance_pack1, 2020.2-maintenance_pack2, 2021.1, 2021.1-maintenance_pack1, and 2021.1-maintenance_pack2 are affected by CVE-2021-27399.
CVE-2021-27399 has a severity rating of 7.8 (high).
To fix the CVE-2021-27399 vulnerability, it is recommended to update to the latest version of Siemens Simcenter Femap.