CVE-2021-27596: Input Validation
Published Mar 22, 2021
·Updated
When a user opens manipulated Autodesk 3D Studio for MS-DOS (.3DS) files received from untrusted sources in SAP 3D Visual Enterprise Viewer, the application crashes and becomes temporarily unavailable to the user until restart of the application.
Affected Software
1 affected component
SAP 3D Visual Enterprise Viewer=9
Event History
Mar 22, 2021
CVE Published
via MITRE·04:58 PM
Data Sourced
via MITRE·04:58 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2021-27596?
CVE-2021-27596 has been classified as medium severity due to potential application crashes.
2
How do I fix CVE-2021-27596?
To mitigate CVE-2021-27596, avoid opening untrusted or manipulated .3DS files in SAP 3D Visual Enterprise Viewer.
3
Which versions of SAP 3D Visual Enterprise Viewer are affected by CVE-2021-27596?
CVE-2021-27596 affects SAP 3D Visual Enterprise Viewer version 9.
4
What happens when CVE-2021-27596 is exploited?
Exploitation of CVE-2021-27596 causes SAP 3D Visual Enterprise Viewer to crash, requiring a restart of the application.
5
Is there a patch or update available for CVE-2021-27596?
As of now, there is no specified patch for CVE-2021-27596, so users should practice safe handling of .3DS files.