First published: Tue Aug 08 2023(Updated: )
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Parasolid V35.1 (All versions < V35.1.171), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.3). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Parasolid | >=34.1<34.1.258 | |
Siemens Parasolid | >=35.0<35.0.254 | |
Siemens Parasolid | >=35.1<35.1.171 | |
Siemens Teamcenter Visualization | >=14.2<14.2.0.6 | |
Siemens Teamcenter Visualization | =14.1 | |
Siemens Teamcenter Visualization | =14.3 | |
Siemens Teamcenter Visualization | >=14.1<14.1.0.11 | |
Siemens Teamcenter Visualization | >=14.3<14.3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2023-38525 is high with a score of 7.8.
CVE-2023-38525 affects versions of Parasolid V34.1 (< V34.1.258), Parasolid V35.0 (< V35.0.254), Parasolid V35.1 (< V35.1.171), Teamcenter Visualization V14.1 (all versions), Teamcenter Visualization V14.2 (< V14.2.0.6), and Teamcenter Visualization V14.3.
The CWE ID of CVE-2023-38525 is 125.
To fix CVE-2023-38525, it is recommended to upgrade to a version higher than or equal to the specified vulnerable versions.
You can find more information about CVE-2023-38525 in the Siemens ProductCERT advisory at https://cert-portal.siemens.com/productcert/pdf/ssa-407785.pdf