CVE-2022-3161: Buffer Overflow
Published Jan 13, 2023
·Updated
The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
Affected Software
8 affected components
Siemens JT2Go<14.1.0.5
Siemens Teamcenter Visualization>=13.3.0<13.3.0.8
Siemens Teamcenter Visualization>=14.0<14.0.0.4
Siemens Teamcenter Visualization>=14.1<14.1.0.5
Siemens JT2Go: All versions prior to V14.1.0.5
Siemens Teamcenter Visualization V13.3: All versions prior to V13.3.0.8
Siemens Teamcenter Visualization V14.0: All versions prior to V14.0.0.4
Siemens Teamcenter Visualization V14.1: All versions prior to V14.1.0.5
Remediation
Information
Siemens released updates for the affected products and recommends updating to the latest versions:
* JT2Go: Update to V14.1.0.5 or later version https://www.plm.automation.siemens.com/global/en/products/plm-components/jt2go.html .
* Teamcenter Visualization V13.3: Update to V13.3.0.8 or later version https://support.sw.siemens.com/ .
* Teamcenter Visualization V14.0: Update to V14.0.0.4 or later version https://support.sw.siemens.com/ .
* Teamcenter Visualization V14.1: Update to V14.1.0.5 or later version https://support.sw.siemens.com/ .
Event History
Jan 13, 2023
CVE Published
via MITRE·12:17 AM
Data Sourced
via MITRE·12:17 AM
RemedyDescriptionSeverityWeakness
Aug 3, 2024
Data Sourced
via ICS·01:06 AM
SeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this memory corruption vulnerability?
The vulnerability ID for this memory corruption vulnerability is CVE-2022-3161.
2
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by parsing specially crafted PDF files.
3
What is the severity of CVE-2022-3161?
The severity of CVE-2022-3161 is high with a score of 7.8.
4
Which software is affected by this vulnerability?
Siemens JT2Go and Siemens Teamcenter Visualization versions up to 14.1.0.5 are affected by this vulnerability.
5
Where can I find more information about this vulnerability?
You can find more information about this vulnerability on the Siemens CERT Portal and the CISA website.