CVE-2021-37180: Siemens Solid Edge Viewer OBJ File Parsing Uninitialized Pointer Remote Code Execution Vulnerability
A vulnerability has been identified in Solid Edge SE2021 (All Versions < SE2021MP7). The PSKERNEL.dll library lacks proper validation while parsing user-supplied OBJ files that could cause an out of bounds access to an uninitialized pointer. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-13775)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Solid Edge SE2021to a version that resolves this vulnerability.Fixed in SE2021MP7 - Compensating control
If upgrading to SE2021MP7 is not immediately possible, restrict exposure to untrusted OBJ files (e.g., only open OBJ files from trusted sources) to reduce the chance an attacker can supply a crafted OBJ file that triggers the PSKERNEL.dll parsing issue.
Event History
Frequently Asked Questions
What is the vulnerability ID for this Siemens Solid Edge Viewer vulnerability?
The vulnerability ID is CVE-2021-37180.
What is the title of this vulnerability?
The title of this vulnerability is 'Siemens Solid Edge Viewer OBJ File Parsing Uninitialized Pointer Remote Code Execution Vulnerability'.
Is user interaction required to exploit this vulnerability?
Yes, user interaction is required to exploit this vulnerability. The target must visit a malicious page or open a malicious file.
What is the severity of CVE-2021-37180?
The severity of CVE-2021-37180 is high with a CVSS score of 7.8.
How can I fix this vulnerability?
To fix this vulnerability, it is recommended to apply the necessary security patches or updates provided by Siemens.