CVE-2022-41280: Null Pointer Dereference
A vulnerability has been identified in JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6). The CGMNISTLoader.dll contains a null pointer dereference vulnerability while parsing specially crafted CGM files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-41280.
What software versions are affected by this vulnerability?
JT2Go (All versions < V14.1.0.6), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.8), Teamcenter Visualization V14.0 (All versions < V14.0.0.4), Teamcenter Visualization V14.1 (All versions < V14.1.0.6).
What is the severity of CVE-2022-41280?
The severity of CVE-2022-41280 is medium with a severity value of 3.3.
How can I fix this vulnerability?
Update your JT2Go and Teamcenter Visualization software to versions V14.1.0.6, V13.2.0.12, V13.3.0.8, V14.0.0.4, and V14.1.0.6 respectively.
Where can I find more information about this vulnerability?
You can find more information about this vulnerability in the Siemens Product Certificates website: https://cert-portal.siemens.com/productcert/pdf/ssa-700053.pdf.