CVE-2022-35904: Low severity bentley microstation vulnerability
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an IFC file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of IFC files could enable an attacker to read information in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-35904.
What is the affected software?
The affected software includes Bentley MicroStation before version 10.17.0.x and Bentley View before version 10.17.0.x.
What is the severity of CVE-2022-35904?
The severity of CVE-2022-35904 is low with a severity value of 3.3.
What is the Common Weakness Enumeration (CWE) ID associated with this vulnerability?
The CWE ID associated with CVE-2022-35904 is CWE-125.
How can I fix the vulnerability?
To fix the vulnerability, it is recommended to update Bentley MicroStation and Bentley View to version 10.17.0.x or above.