CVE-2022-35905: Low severity bentley microstation vulnerability
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an FBX file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of FBX files could enable an attacker to read information in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2022-35905.
What is the severity of CVE-2022-35905?
The severity of CVE-2022-35905 is low.
What software versions are affected by CVE-2022-35905?
Bentley MicroStation before version 10.17.0.x and Bentley View before version 10.17.0.x are affected by CVE-2022-35905.
How can CVE-2022-35905 be exploited?
CVE-2022-35905 can be exploited by using an affected version of MicroStation or MicroStation-based application to open an FBX file containing crafted data.
Is there a fix available for CVE-2022-35905?
Yes, upgrading to version 10.17.0.x or higher of Bentley MicroStation or Bentley View resolves CVE-2022-35905.