First published: Tue Jun 13 2023(Updated: )
A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8), Teamcenter Visualization V14.2 (All versions < V14.2.0.3). The affected applications contain an out of bounds read past the end of an allocated buffer while parsing a specially crafted CGM file. This vulnerability could allow an attacker to disclose sensitive information.
Credit: productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens JT2Go | <14.2.0.3 | |
Siemens Teamcenter Visualization | >=13.2.0<13.2.0.13 | |
Siemens Teamcenter Visualization | >=13.3.0<13.3.0.10 | |
Siemens Teamcenter Visualization | >=14.0<14.0.0.6 | |
Siemens Teamcenter Visualization | >=14.1<14.1.0.8 | |
Siemens Teamcenter Visualization | >=14.2<14.2.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2023-33122.
The affected software for this vulnerability is JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), and Teamcenter Visualization V14.1 (All versions < V14.1.0.8).
The severity level of CVE-2023-33122 is medium.
To fix the vulnerability in JT2Go, upgrade to version V14.2.0.3 or later.
To fix the vulnerability in Teamcenter Visualization, upgrade to the respective versions: V13.2.0.13 or later for V13.2, V13.3.0.10 or later for V13.3, V14.0.0.6 or later for V14.0, and V14.1.0.8 or later for V14.1.