CVE-2022-3160: High severity siemens jt2go vulnerability
The APDFL.dll contains an out-of-bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2022-3160?
The severity of CVE-2022-3160 is high with a CVSS score of 7.8.
Which software is affected by CVE-2022-3160?
Siemens JT2Go and Siemens Teamcenter Visualization versions up to 14.1.0.5 are affected by CVE-2022-3160.
What is the vulnerability description of CVE-2022-3160?
CVE-2022-3160 is a vulnerability in APDFL.dll that allows an attacker to execute code in the context of the current process by exploiting an out-of-bounds write past a fixed-length heap-based buffer while parsing specially crafted PDF files.
How can I fix CVE-2022-3160?
Update Siemens JT2Go and Siemens Teamcenter Visualization to versions higher than or equal to 14.1.0.5 to mitigate CVE-2022-3160.
Where can I find more information about CVE-2022-3160?
You can find more information about CVE-2022-3160 on the Siemens ProductCERT website and the CISA ICS advisories page.