CVE-2023-22295: Medium severity datakit crosscad/ware vulnerability
Published Apr 20, 2023
·Updated
Datakit CrossCadWarex64.dll contains an out of bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.
Affected Software
2 affected componentsFixes available
Datakit CrossCAD/Ware_x64 library<2023.1
2023.1
Datakit CrossCadWare<2023.1
Remediation
Information
Datakit recommends user upgrade to v2023.1 https://www.datakit.com/en/crosscad_ware.php or later.
Event History
Apr 20, 2023
CVE Published
via MITRE·06:09 PM
Data Sourced
via MITRE·06:09 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID for this vulnerability is CVE-2023-22295.
2
What is the severity of CVE-2023-22295?
The severity of CVE-2023-22295 is medium with a CVSS score of 5.5.
3
Which software is affected by CVE-2023-22295?
The Datakit CrossCadWare (version up to exclusive 2023.1) software is affected by CVE-2023-22295.
4
What is the impact of CVE-2023-22295?
CVE-2023-22295 could allow an attacker to disclose sensitive information.
5
Is there a fix available for CVE-2023-22295?
At the moment, there is no available fix for CVE-2023-22295. It is recommended to follow the recommendations from the vendor or software provider.