CVE-2022-28808: High severity opendesign drawings software development kit vulnerability
An issue was discovered in Open Design Alliance Drawings SDK before 2023.3. An Out-of-Bounds Read vulnerability exists when reading DWG files in a recovery mode. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-28808?
CVE-2022-28808 is a vulnerability discovered in Open Design Alliance Drawings SDK before 2023.3 which allows for an Out-of-Bounds Read when reading DWG files in recovery mode.
How severe is CVE-2022-28808?
CVE-2022-28808 has a severity rating of 7.8 out of 10, indicating a high severity.
What software is affected by CVE-2022-28808?
The Open Design Alliance Drawings SDK before 2023.3 is affected by CVE-2022-28808.
How can CVE-2022-28808 be exploited?
An attacker can exploit CVE-2022-28808 by leveraging the vulnerability to execute code in the context of the current process.
Is there a fix available for CVE-2022-28808?
It is recommended to update to Open Design Alliance Drawings SDK 2023.3 or later to mitigate the risk associated with CVE-2022-28808.