CVE-2023-22354: Datakit CrossCAD/Ware
Datakit CrossCadWarex64.dll contains an out-of-bounds read past the end of an allocated buffer while parsing a specially crafted SLDPRT file. This vulnerability could allow an attacker to disclose sensitive information.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2023-22354?
CVE-2023-22354 is a vulnerability in Datakit CrossCadWare_x64.dll that allows an attacker to disclose sensitive information.
How does CVE-2023-22354 affect Datakit CrossCadWare?
CVE-2023-22354 affects Datakit CrossCadWare version up to exclusive 2023.1 and can lead to an out-of-bounds read past the end of an allocated buffer.
What is the severity of CVE-2023-22354?
CVE-2023-22354 has a severity rating of 5.5 (medium).
How can an attacker exploit CVE-2023-22354?
An attacker can exploit CVE-2023-22354 by using a specially crafted SLDPRT file to trigger the out-of-bounds read vulnerability in Datakit CrossCadWare_x64.dll.
Is there a fix available for CVE-2023-22354?
At the moment, there is no available fix for CVE-2023-22354. It is recommended to follow the guidance provided by the software vendor or security advisories.