CVE-2021-41538: Siemens Solid Edge Viewer OBJ File Parsing Uninitialized Pointer Information Disclosure Vulnerability
A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All versions < V1988), Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to information disclosure by unexpected access to an uninitialized pointer while parsing user-supplied OBJ files. An attacker could leverage this vulnerability to leak information from unexpected memory locations (ZDI-CAN-13770).
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
NX 1953 Seriesto a version that resolves this vulnerability.Fixed in V1973.3700Patch ZDI-CAN-13770 - Upgrade
Upgrade
NX 1980 Seriesto a version that resolves this vulnerability.Fixed in V1988Patch ZDI-CAN-13770 - Upgrade
Upgrade
Solid Edge SE2021to a version that resolves this vulnerability.Fixed in SE2021MP8Patch ZDI-CAN-13770
Event History
Frequently Asked Questions
What is the vulnerability ID of this Siemens Solid Edge Viewer vulnerability?
The vulnerability ID of this Siemens Solid Edge Viewer vulnerability is CVE-2021-41538.
What is the affected software for this vulnerability?
The affected software for this vulnerability is Siemens Solid Edge Viewer.
How can the vulnerability CVE-2021-41538 be exploited?
The vulnerability CVE-2021-41538 can be exploited by remote attackers who trick a user to visit a malicious page or open a malicious file.
What is the severity of vulnerability CVE-2021-41538?
The severity of vulnerability CVE-2021-41538 is medium with a severity value of 3.3.
Where can I find more information about vulnerability CVE-2021-41538?
You can find more information about vulnerability CVE-2021-41538 in the following references: [link1], [link2], [link3].