First published: Tue Sep 12 2023(Updated: )
A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.1), Tecnomatix Plant Simulation V2201 (All versions < V2201.0010), Tecnomatix Plant Simulation V2302 (All versions < V2302.0004). The affected application contains a type confusion vulnerability while parsing WRL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20826)
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens JT2Go | <14.3.0.1 | |
Siemens Teamcenter Visualization | >=13.3.0<13.4.0.12 | |
Siemens Teamcenter Visualization | >=14.0<14.1.0.11 | |
Siemens Teamcenter Visualization | >=14.2<14.2.0.6 | |
Siemens Teamcenter Visualization | >=14.3<14.3.0.1 | |
Siemens Tecnomatix Plant Simulation | >=2201.0<2201.0010 | |
Siemens Tecnomatix Plant Simulation | >=2302.0<2302.0004 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-38073 is high with a severity value of 7.8.
CVE-2023-38073 affects JT2Go versions < V14.3.0.1, Teamcenter Visualization V13.3 versions < V13.3.0.12, Teamcenter Visualization V14.0 versions, Teamcenter Visualization V14.1 versions < V14.1.0.11, and Teamcenter Visualization V14.2 versions < V14.2.0.6.
To fix CVE-2023-38073, update JT2Go and Teamcenter Visualization to versions V14.3.0.1, V13.3.0.12, V14.0, V14.1.0.11, or V14.2.0.6 or later.
The CWE ID for CVE-2023-38073 is 843.
More information about CVE-2023-38073 can be found in the [Siemens CERT Portal PDF](https://cert-portal.siemens.com/productcert/pdf/ssa-278349.pdf).