CVE-2021-34332: Medium severity siemens jt2go vulnerability
A vulnerability has been identified in JT2Go (All versions < V13.2), Teamcenter Visualization (All versions < V13.2). The BMPLoader.dll library in affected applications lacks proper validation of user-supplied data when parsing BMP files. A malformed input file could result in an infinite loop condition that leads to denial of service condition. An attacker could leverage this vulnerability to consume excessive resources. (CNVD-C-2021-79300)
Affected Software
Event History
Frequently Asked Questions
What are the affected versions of CVE-2021-34332?
CVE-2021-34332 affects all versions of JT2Go and Teamcenter Visualization prior to version 13.2.
What is the main issue described in CVE-2021-34332?
CVE-2021-34332 involves improper validation of user-supplied data in the BMP_Loader.dll library, leading to potential infinite loops when handling malformed BMP files.
How do I mitigate CVE-2021-34332?
To mitigate CVE-2021-34332, update JT2Go and Teamcenter Visualization to version 13.2 or later.
Are there any potential impacts of CVE-2021-34332?
The vulnerability could cause an infinite loop, potentially leading to denial of service in affected applications.
Who is the vendor for the products affected by CVE-2021-34332?
The vendor for the affected products is Siemens.