First published: Tue Aug 10 2021(Updated: )
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). An XML external entity injection vulnerability in the underlying XML parser could cause the affected application to disclose arbitrary files to remote attackers by loading a specially crafted xml file.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Solid Edge Se2021 Firmware | <se2021mp7 | |
Siemens Solid Edge Se2021 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-37178.
The severity of CVE-2021-37178 is medium with a CVSS score of 5.5.
The affected software for CVE-2021-37178 is Siemens Solid Edge SE2021 (All Versions < SE2021MP7).
CVE-2021-37178 is an XML external entity injection vulnerability in the underlying XML parser of Siemens Solid Edge SE2021 (All Versions < SE2021MP7), which could allow remote attackers to disclose arbitrary files.
Yes, the fix for CVE-2021-37178 is to update to Solid Edge SE2021MP7 or a later version.