CVE-2021-44450: High severity siemens jt open vulnerability
A vulnerability has been identified in JT Utilities (All versions < V12.8.1.1), JTTK (All versions < V10.8.1.1). JTTK library in affected products is vulnerable to an out of bounds read past the end of an allocated buffer when parsing JT files. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-15055, ZDI-CAN-14915, ZDI-CAN-14865)
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44450?
The severity of CVE-2021-44450 is high.
Which products and versions are affected by CVE-2021-44450?
Siemens JT Utilities versions prior to V12.8.1.1 and Siemens JTTK versions prior to V10.8.1.1 are affected by CVE-2021-44450.
What is the vulnerability in Siemens JT Utilities and JTTK?
The vulnerability in Siemens JT Utilities and JTTK is an out-of-bounds read past the end of an allocated buffer when parsing JT files, which could lead to information leakage.
How can an attacker exploit CVE-2021-44450?
An attacker can exploit CVE-2021-44450 by leveraging the vulnerability to leak information.
Is there a fix available for CVE-2021-44450?
Yes, updating Siemens JT Utilities to V12.8.1.1 and Siemens JTTK to V10.8.1.1 will fix CVE-2021-44450.