CVE-2021-41535: Siemens Solid Edge Viewer OBJ File Parsing Use-After-Free Remote Code Execution Vulnerability
A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All versions < V1988), Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13771).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NX 1953 Seriesto a version that resolves this vulnerability.Fixed in V1973.3700 - Upgrade
Upgrade
NX 1980 Seriesto a version that resolves this vulnerability.Fixed in V1988 - Upgrade
Upgrade
Solid Edge SE2021to a version that resolves this vulnerability.Fixed in SE2021MP8
Event History
Frequently Asked Questions
What is CVE-2021-41535?
CVE-2021-41535 is a vulnerability that allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer.
How severe is CVE-2021-41535?
CVE-2021-41535 has a severity rating of 7.8 (high).
What is the affected software?
The affected software is Siemens Solid Edge Viewer.
Is user interaction required to exploit CVE-2021-41535?
Yes, user interaction is required to exploit this vulnerability.
Are there any references for more information?
Yes, you can find more information about CVE-2021-41535 at the following references: [link1], [link2], [link3].