CVE-2022-42900: High severity Bentley MicroStation vulnerability
Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read issues when opening crafted FBX files. Exploiting these issues could lead to information disclosure and code execution. The fixed versions are 10.17.01.58 for MicroStation and 10.17.01.19 for Bentley View.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Bentley MicroStation / MicroStation-based applicationsto a version that resolves this vulnerability.Fixed in 10.17.01.58* - Upgrade
Upgrade
Bentley Viewto a version that resolves this vulnerability.Fixed in 10.17.01.19*
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2022-42900.
What is the severity rating of CVE-2022-42900?
CVE-2022-42900 has a severity rating of 7.8, indicating a high severity.
Which software versions are affected by CVE-2022-42900?
Bentley MicroStation versions up to 10.17.01.58 and Bentley View versions up to 10.17.01.19 are affected by CVE-2022-42900.
What is the impact of CVE-2022-42900?
Exploiting CVE-2022-42900 could lead to information disclosure and code execution.
How can I mitigate CVE-2022-42900?
To mitigate CVE-2022-42900, update Bentley MicroStation to version 10.17.01.58 or higher, and Bentley View to version 10.17.01.19 or higher.