First published: Tue Aug 08 2023(Updated: )
A vulnerability has been identified in JT2Go (All versions < V14.2.0.5), Solid Edge SE2022 (All versions < V222.0 Update 13), Solid Edge SE2023 (All versions < V223.0 Update 4), Teamcenter Visualization V13.2 (All versions < V13.2.0.15), Teamcenter Visualization V13.3 (All versions < V13.3.0.11), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.5). The affected application contains a use-after-free vulnerability that could be triggered while parsing specially crafted ASM file. An attacker could leverage this vulnerability to execute code in the context of the current process.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens JT2Go | <14.2.0.5 | |
Siemens Teamcenter Visualization | >=13.2.0<13.2.0.15 | |
Siemens Teamcenter Visualization | >=13.3.0<13.3.0.11 | |
Siemens Teamcenter Visualization | >=14.1<14.1.0.11 | |
Siemens Teamcenter Visualization | >=14.2<14.2.0.5 | |
Siemens Solid Edge Se2022 | ||
Siemens Solid Edge Se2022 | =maintenance_pack_1 | |
Siemens Solid Edge Se2022 | =maintenance_pack_2 | |
Siemens Solid Edge Se2022 | =maintenance_pack_3 | |
Siemens Solid Edge Se2022 | =maintenance_pack_4 | |
Siemens Solid Edge Se2022 | =maintenance_pack_5 | |
Siemens Solid Edge Se2022 | =maintenance_pack_7 | |
Siemens Solid Edge Se2022 | =maintenance_pack_8 | |
Siemens Solid Edge Se2022 | =maintenance_pack_9 | |
Siemens Solid Edge Se2022 | =maintenance_pack_10 | |
Siemens Solid Edge Se2022 | =maintenance_pack_11 | |
Siemens Solid Edge Se2022 | =maintenance_pack_12 | |
Siemens Solid Edge Se2023 | ||
Siemens Solid Edge Se2023 | =update_0001 | |
Siemens Solid Edge Se2023 | =update_0002 | |
Siemens Solid Edge Se2023 | =update_0003 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-28830 is high with a CVSS score of 7.8.
CVE-2023-28830 affects JT2Go (versions < V14.2.0.5), Solid Edge SE2022 (versions < V222.0 Update 13), Solid Edge SE2023 (versions < V223.0 Update 4), Teamcenter Visualization V13.2 (versions < V13.2.0.15), Teamcenter Visualization V13.3 (versions < V13.3.0.11), and more.
To mitigate CVE-2023-28830, it is recommended to update JT2Go to V14.2.0.5 or higher, Solid Edge SE2022 to V222.0 Update 13 or higher, Solid Edge SE2023 to V223.0 Update 4 or higher, and Teamcenter Visualization to V13.2.0.15 or higher.
CWE-416 is a vulnerability that occurs when relying on a location that is not memory controllable.
More information about CVE-2023-28830 can be found at the following link: [https://cert-portal.siemens.com/productcert/pdf/ssa-131450.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-131450.pdf)