CVE-2021-44442: High severity siemens jt open vulnerability
Published Dec 14, 2021
·Updated
A vulnerability has been identified in JT Utilities (All versions < V13.1.1.0), JTTK (All versions < V11.1.1.0). JTTK library in affected products contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-14995)
Affected Software
2 affected components
Siemens Jt Open Toolkit<11.1.1.0
Siemens Jt Utilities<13.1.1.0
Event History
Dec 14, 2021
CVE Published
via MITRE·12:07 PM
Data Sourced
via MITRE·12:07 PM
DescriptionWeakness
Data Sourced
via NVD·12:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID is CVE-2021-44442.
2
What software versions are affected by this vulnerability?
Affected software versions are JT Utilities < V13.1.1.0 and JTTK < V11.1.1.0.
3
What is the severity of CVE-2021-44442?
The severity of CVE-2021-44442 is high with a CVSS score of 7.8.
4
How does this vulnerability occur?
This vulnerability occurs due to an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted JT files.
5
How can an attacker exploit CVE-2021-44442?
An attacker can exploit CVE-2021-44442 to execute arbitrary code.