CVE-2022-41613: High severity bentley systems vulnerability
Bentley Systems MicroStation Connect versions
10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when parsing DGN files, which may allow an attacker to crash the product, disclose sensitive information, or execute arbitrary code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2022-41613?
CVE-2022-41613 is a vulnerability in Bentley Systems MicroStation Connect versions 10.17.0.209 and prior that allows an attacker to crash the product, disclose sensitive information, or execute arbitrary code.
How does CVE-2022-41613 affect Bentley Systems MicroStation Connect?
CVE-2022-41613 affects Bentley Systems MicroStation Connect versions 10.17.0.209 and prior by causing an Out-of-Bounds Read vulnerability when parsing DGN files.
What is the severity of CVE-2022-41613?
CVE-2022-41613 has a severity rating of 7.8, which is considered high.
How can an attacker exploit CVE-2022-41613?
An attacker can exploit CVE-2022-41613 by crafting a malicious DGN file that triggers the Out-of-Bounds Read vulnerability in Bentley Systems MicroStation Connect.
Is there a fix or patch available for CVE-2022-41613?
A fix or patch for CVE-2022-41613 is not currently available. It is recommended to follow the mitigation steps provided by the vendor and monitor for updates.