First published: Tue Aug 08 2023(Updated: )
A vulnerability has been identified in Parasolid V34.1 (All versions < V34.1.258), Parasolid V35.0 (All versions < V35.0.254), Teamcenter Visualization V14.1 (All versions), Teamcenter Visualization V14.2 (All versions < V14.2.0.12), Teamcenter Visualization V14.3 (All versions < V14.3.0.9), Teamcenter Visualization V2312 (All versions < V2312.0004). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Parasolid | >=34.1<34.1.258 | |
Siemens Parasolid | >=35.0<35.0.254 | |
Siemens Teamcenter Visualization | >=14.2<14.2.0.6 | |
Siemens Teamcenter Visualization | =14.1 | |
Siemens Teamcenter Visualization | =14.3 | |
Siemens Teamcenter Visualization | >=14.1<14.1.0.11 | |
Siemens Teamcenter Visualization | >=14.3<14.3.0.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of the CVE-2023-38527 vulnerability is high (7.8).
The CVE-2023-38527 vulnerability affects Parasolid V34.1 (versions < V34.1.258), Parasolid V35.0 (versions < V35.0.254), Teamcenter Visualization V14.1 (all versions), Teamcenter Visualization V14.2 (versions < V14.2.0.6), and Teamcenter Visualization V14.3 (all versions).
The CWE of the CVE-2023-38527 vulnerability is 125.
To fix the CVE-2023-38527 vulnerability, it is recommended to update the affected software versions to the latest available patches or versions provided by Siemens.
More information about the CVE-2023-38527 vulnerability can be found in the Siemens CERT Portal PDF: https://cert-portal.siemens.com/productcert/pdf/ssa-407785.pdf.