First published: Thu Apr 20 2023(Updated: )
Datakit CrossCadWare_x64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Datakit CrossCadWare | <2023.1 | |
Datakit CrossCAD/Ware_x64 library | <2023.1 | 2023.1 |
Datakit recommends user upgrade to v2023.1 https://www.datakit.com/en/crosscad_ware.php or later.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22354 is a vulnerability in Datakit CrossCadWare_x64.dll that allows an attacker to disclose sensitive information.
CVE-2023-22354 affects Datakit CrossCadWare version up to exclusive 2023.1 and can lead to an out-of-bounds read past the end of an allocated buffer.
CVE-2023-22354 has a severity rating of 5.5 (medium).
An attacker can exploit CVE-2023-22354 by using a specially crafted SLDPRT file to trigger the out-of-bounds read vulnerability in Datakit CrossCadWare_x64.dll.
At the moment, there is no available fix for CVE-2023-22354. It is recommended to follow the guidance provided by the software vendor or security advisories.