CVE-2021-37178: XEE
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). An XML external entity injection vulnerability in the underlying XML parser could cause the affected application to disclose arbitrary files to remote attackers by loading a specially crafted xml file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Solid Edge SE2021to a version that resolves this vulnerability.Fixed in SE2021MP7
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2021-37178.
What is the severity of CVE-2021-37178?
The severity of CVE-2021-37178 is medium with a CVSS score of 5.5.
What is the affected software for CVE-2021-37178?
The affected software for CVE-2021-37178 is Siemens Solid Edge SE2021 (All Versions < SE2021MP7).
How does CVE-2021-37178 impact the affected software?
CVE-2021-37178 is an XML external entity injection vulnerability in the underlying XML parser of Siemens Solid Edge SE2021 (All Versions < SE2021MP7), which could allow remote attackers to disclose arbitrary files.
Is there a fix available for CVE-2021-37178?
Yes, the fix for CVE-2021-37178 is to update to Solid Edge SE2021MP7 or a later version.