CVE-2022-41851: High severity Siemens Jt Open Toolkit vulnerability
A vulnerability has been identified in JTTK (All versions < V11.1.1.0), Simcenter Femap V2022.1 (All versions < V2022.1.3), Simcenter Femap V2022.2 (All versions < V2022.2.2). The JTTK library is vulnerable to an uninitialized pointer reference vulnerability while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-16973)
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
JTTKto a version that resolves this vulnerability.Fixed in V11.1.1.0 - Upgrade
Upgrade
Simcenter Femap V2022.1to a version that resolves this vulnerability.Fixed in V2022.1.3 - Upgrade
Upgrade
Simcenter Femap V2022.2to a version that resolves this vulnerability.Fixed in V2022.2.2
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2022-41851.
What is the severity of CVE-2022-41851?
The severity of CVE-2022-41851 is high with a CVSS score of 7.8.
Which software versions are affected by CVE-2022-41851?
All versions of JTTK < V11.1.1.0, Simcenter Femap V2022.1 < V2022.1.3, and Simcenter Femap V2022.2 < V2022.2.2 are affected by CVE-2022-41851.
What is the CWE ID for this vulnerability?
The CWE ID for this vulnerability is CWE-824.
How can I fix CVE-2022-41851?
To fix CVE-2022-41851, it is recommended to upgrade JTTK to version 11.1.1.0 or later, Simcenter Femap V2022.1 to version 2022.1.3 or later, and Simcenter Femap V2022.2 to version 2022.2.2 or later.