CVE-2021-41534: Siemens Solid Edge Viewer JT File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
A vulnerability has been identified in NX 1980 Series (All versions < V1984), Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this vulnerability to leak information in the context of the current process (ZDI-CAN-13703).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NX 1980 Seriesto a version that resolves this vulnerability.Fixed in V1984 - Upgrade
Upgrade
Solid Edge SE2021to a version that resolves this vulnerability.Patch SE2021MP8
Event History
Frequently Asked Questions
What is the vulnerability ID for this Siemens Solid Edge Viewer vulnerability?
The vulnerability ID for this Siemens Solid Edge Viewer vulnerability is CVE-2021-41534.
What is the severity rating of CVE-2021-41534?
CVE-2021-41534 has a severity rating of 3.3 (medium).
How does this vulnerability allow attackers to disclose sensitive information?
This vulnerability allows remote attackers to disclose sensitive information by exploiting a flaw in Siemens Solid Edge Viewer's JT file parsing, requiring user interaction.
How can an attacker exploit CVE-2021-41534?
An attacker can exploit CVE-2021-41534 by tricking the target into visiting a malicious page or opening a malicious file.
Is there a fix available for this vulnerability?
Yes, Siemens has released security advisories with fixes for CVE-2021-41534. Please refer to the provided references for more information.