First published: Tue Sep 13 2022(Updated: )
A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.161), Parasolid V35.0 (All versions >= V35.0.161 < V35.0.164), Simcenter Femap V2022.1 (All versions < V2022.1.3), Simcenter Femap V2022.2 (All versions < V2022.2.2). The affected application is vulnerable to out of bounds read past the end of an allocated buffer when parsing X_T files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-18196)
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Simcenter Femap | >=2022.1<2022.1.3 | |
Siemens Simcenter Femap | >=2022.2<2022.2.2 | |
Siemens Parasolid | >=33.1<33.1.262 | |
Siemens Parasolid | >=34.0<34.0.252 | |
Siemens Parasolid | >=34.1<34.1.242 | |
Siemens Parasolid | >=35.0<35.0.164 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2022-39156 is high with a severity value of 7.8.
Siemens Simcenter Femap versions 2022.1 through 2022.1.3 and 2022.2 through 2022.2.2, Siemens Parasolid versions 33.1 through 33.1.262, 34.0 through 34.0.252, and 34.1 through 34.1.242 are affected by CVE-2022-39156.
Update Siemens Simcenter Femap to version 2022.2.3 or later, and update Siemens Parasolid to version 35.0.165 or later to fix CVE-2022-39156.
You can find more information about CVE-2022-39156 in the Siemens ProductCERT advisory at the following link: [https://cert-portal.siemens.com/productcert/pdf/ssa-518824.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-518824.pdf)
The Common Weakness Enumeration (CWE) for CVE-2022-39156 is CWE-125.