CVE-2023-22321: Datakit CrossCAD/Ware
Published Apr 20, 2023
·Updated
Datakit CrossCadWarex64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.
Affected Software
2 affected componentsFixes available
Datakit CrossCAD/Ware_x64 library<2023.1
2023.1
Datakit CrossCadWare<2023.1
Remediation
Information
Datakit recommends user upgrade to v2023.1 https://www.datakit.com/en/crosscad_ware.php or later.
Event History
Apr 20, 2023
CVE Published
via MITRE·06:12 PM
Data Sourced
via MITRE·06:12 PM
RemedyDescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2023-22321.
2
What is the name of the affected software?
The affected software is Datakit CrossCadWare.
3
What is the severity of CVE-2023-22321?
The severity of CVE-2023-22321 is medium with a severity value of 5.5.
4
How can an attacker exploit this vulnerability?
An attacker can exploit this vulnerability by parsing a specially crafted SLDPRT file, causing an out-of-bounds read past the end of an allocated buffer in the Datakit CrossCadWare_x64.dll.
5
Is there any fix available for this vulnerability?
Ensure that you are using Datakit CrossCadWare version 2023.1 or above, as these versions have addressed the vulnerability.