First published: Thu Apr 20 2023(Updated: )
Datakit CrossCadWare_x64.dll contains an out of bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Datakit CrossCadWare | <2023.1 | |
Datakit CrossCAD/Ware_x64 library | <2023.1 | 2023.1 |
Datakit recommends user upgrade to v2023.1 https://www.datakit.com/en/crosscad_ware.php or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-22295.
The severity of CVE-2023-22295 is medium with a CVSS score of 5.5.
The Datakit CrossCadWare (version up to exclusive 2023.1) software is affected by CVE-2023-22295.
CVE-2023-22295 could allow an attacker to disclose sensitive information.
At the moment, there is no available fix for CVE-2023-22295. It is recommended to follow the recommendations from the vendor or software provider.