First published: Tue Sep 13 2022(Updated: )
A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.161), Parasolid V35.0 (All versions >= V35.0.161 < V35.0.164), Simcenter Femap V2022.1 (All versions < V2022.1.3), Simcenter Femap V2022.2 (All versions < V2022.2.2). The affected application is vulnerable to out of bounds read past the end of an allocated buffer when parsing X_T files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-17496)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simcenter Femap | >=2022.1<2022.1.3 | |
Siemens Simcenter Femap | >=2022.2<2022.2.2 | |
Siemens Parasolid | >=33.1<33.1.263 | |
Siemens Parasolid | >=34.0<34.0.252 | |
Siemens Parasolid | >=34.1<34.1.242 | |
Siemens Parasolid | >=35.0<35.0.164 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-39145.
The severity of CVE-2022-39145 is rated as high, with a CVSS score of 7.8.
The affected software versions include Siemens Simcenter Femap versions 2022.1.0 to 2022.1.3, and 2022.2.0 to 2022.2.2. Additionally, Parasolid versions 33.1.0 to 33.1.262, 33.1.263, 34.0.0 to 34.0.252, 34.1.0 to 34.1.242, and 35.0.0 to 35.0.161.
The official reference for CVE-2022-39145 can be found at [this link](https://cert-portal.siemens.com/productcert/pdf/ssa-518824.pdf).
The Common Weakness Enumeration (CWE) ID for CVE-2022-39145 is CWE-125.