CVE-2021-37203: High severity Siemens Nx 1980 vulnerability
A vulnerability has been identified in NX 1980 Series (All versions < V1984), Solid Edge SE2021 (All versions < SE2021MP8). The plmxmlAdapterIFC.dll contains an out-of-bounds read while parsing user supplied IFC files which could result in a read past the end of an allocated buffer. This could allow an attacker to cause a denial-of-service condition or read sensitive information from memory locations.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NX 1980 Seriesto a version that resolves this vulnerability.Fixed in V1984 - Upgrade
Upgrade
Solid Edge SE2021to a version that resolves this vulnerability.Patch SE2021MP8
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2021-37203.
What is the severity of CVE-2021-37203?
The severity of CVE-2021-37203 is high with a CVSS score of 7.1.
Which software versions are affected by CVE-2021-37203?
NX 1980 Series (versions < V1984) and Solid Edge SE2021 (versions < SE2021MP8) are affected by CVE-2021-37203.
What is the nature of the vulnerability in CVE-2021-37203?
The plmxmlAdapterIFC.dll contains an out-of-bounds read while parsing user supplied IFC files, leading to a read past the end of an allocated buffer.
Are there any available fixes for CVE-2021-37203?
Siemens has released security advisories (SSA-208530 and SSA-728618) with mitigation measures for CVE-2021-37203.