First published: Tue Aug 10 2021(Updated: )
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). The PSKERNEL.dll library in affected application lacks proper validation while parsing user-supplied OBJ files that could lead to a use-after-free condition. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13777)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Solid Edge Se2021 Firmware | <se2021mp7 | |
Siemens Solid Edge Se2021 | ||
Siemens Solid Edge Viewer |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this Siemens Solid Edge Viewer vulnerability is CVE-2021-37179.
The severity of CVE-2021-37179 is high with a severity value of 7.8.
CVE-2021-37179 allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer.
Siemens Solid Edge Viewer and Siemens Solid Edge Se2021 Firmware (up to and excluding version se2021mp7) are affected by CVE-2021-37179.
User interaction is required to exploit CVE-2021-37179 by visiting a malicious page or opening a malicious file.