CVE-2022-28661: High severity siemens simcenter femap vulnerability
A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.2). The affected application contains an out of bounds read past the end of an allocated buffer while parsing specially crafted .NEU files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15114)
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the vulnerability ID for this Simcenter Femap vulnerability?
The vulnerability ID for this Simcenter Femap vulnerability is CVE-2022-28661.
What is the severity of CVE-2022-28661?
The severity of CVE-2022-28661 is high.
What is the affected software for CVE-2022-28661?
The affected software for CVE-2022-28661 is Siemens Simcenter Femap all versions prior to V2022.1.2.
How does CVE-2022-28661 work?
CVE-2022-28661 works by exploiting an out of bounds read past the end of an allocated buffer while parsing specially crafted .NEU files in Simcenter Femap.
How can I fix CVE-2022-28661?
To fix CVE-2022-28661, users should update to version V2022.1.2 or higher of Siemens Simcenter Femap.