First published: Tue Apr 12 2022(Updated: )
A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.2). The affected application contains an out of bounds write past the end of an allocated buffer while parsing specially crafted .NEU files. This could allow an attacker to leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-15307)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simcenter Femap | <2022.1.2 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2022-28662.
All versions of Simcenter Femap before V2022.1.2 are affected by this vulnerability.
This vulnerability has a severity rating of medium.
The CWE ID for this vulnerability is CWE-787.
An attacker can leverage this vulnerability by parsing specially crafted .NEU files to trigger an out-of-bounds write past the end of an allocated buffer.