CVE-2021-41533: Siemens Solid Edge Viewer JT File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
A vulnerability has been identified in NX 1980 Series (All versions < V1984), Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this vulnerability to leak information in the context of the current process (ZDI-CAN-13565).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Siemens NX 1980 Seriesto a version that resolves this vulnerability.Fixed in V1984 - Upgrade
Upgrade
Solid Edge SE2021to a version that resolves this vulnerability.Patch SE2021MP8 - Compensating control
Mitigate exposure by limiting/validating JT file inputs to trusted sources before the affected applications parse them (out-of-bounds read while parsing JT files).
Event History
Frequently Asked Questions
What is the vulnerability ID for this Siemens Solid Edge Viewer vulnerability?
The vulnerability ID for this Siemens Solid Edge Viewer vulnerability is CVE-2021-41533.
What is the severity of CVE-2021-41533?
The severity of CVE-2021-41533 is medium with a severity value of 3.3.
How can remote attackers exploit the vulnerability CVE-2021-41533?
Remote attackers can exploit the vulnerability CVE-2021-41533 by tricking the target into visiting a malicious page or opening a malicious file.
Which software is affected by the Siemens Solid Edge Viewer vulnerability CVE-2021-41533?
The Siemens Solid Edge Viewer software versions se2021 up to se2021-maintenance_pack7 are affected by the vulnerability CVE-2021-41533.
How can I fix the vulnerability CVE-2021-41533 in Siemens Solid Edge Viewer?
To fix the vulnerability CVE-2021-41533 in Siemens Solid Edge Viewer, it is recommended to update to the latest version of the software available from Siemens.