CVE-2023-39187: High severity solid edge se2025 vulnerability
Published Aug 8, 2023
·Updated
A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 7). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted DFT files. This could allow an attacker to execute code in the context of the current process.
Affected Software
8 affected components
Siemens Solid Edge<se2023
Siemens Solid Edge=se2023
Siemens Solid Edge=se2023-maintenance_pack1
Siemens Solid Edge=se2023-maintenance_pack2
Siemens Solid Edge=se2023-maintenance_pack3
Siemens Solid Edge=se2023-maintenance_pack4
Siemens Solid Edge=se2023-maintenance_pack5
Siemens Solid Edge=se2023-maintenance_pack6
Event History
Aug 8, 2023
CVE Published
via MITRE·09:20 AM
Data Sourced
via MITRE·09:20 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2023-39187.
2
What is the severity of CVE-2023-39187?
The severity of CVE-2023-39187 is high.
3
Which versions of Solid Edge are affected by CVE-2023-39187?
All versions of Solid Edge SE2023 with a version number lower than V223.0 Update 7 are affected by CVE-2023-39187.
4
What is the impact of CVE-2023-39187?
CVE-2023-39187 allows an attacker to execute code in the context of the current user.
5
Is there a fix available for CVE-2023-39187?
Yes, Siemens has released an update to address this vulnerability. Please refer to the Siemens ProductCERT website for more information.