First published: Tue Sep 12 2023(Updated: )
A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.260), Parasolid V35.1 (All versions < V35.1.246), Parasolid V36.0 (All versions < V36.0.156), Simcenter Femap V2301 (All versions < V2301.0003), Simcenter Femap V2306 (All versions < V2306.0001). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-21266)
Credit: productcert@siemens.com productcert@siemens.com
Affected Software | Affected Version | How to fix |
---|---|---|
Siemens Parasolid | >=35.0<35.0.260 | |
Siemens Parasolid | >=35.1<35.1.246 | |
Siemens Parasolid | >=36.0<36.0.156 | |
Siemens Simcenter Femap | >=2301.0<2301.0003 | |
Siemens Simcenter Femap | >=2306.0<2306.0001 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2023-41033.
The severity of CVE-2023-41033 is high, with a severity value of 7.8.
All versions of Parasolid V35.0 (less than V35.0.260), Parasolid V35.1 (less than V35.1.246), and Parasolid V36.0 (less than V36.0.156) are affected by CVE-2023-41033.
CVE-2023-41033 is a vulnerability in Parasolid that allows an out of bounds write past the end of an allocated structure when parsing specially crafted X files.
Yes, you can refer to the following link for more information: [https://cert-portal.siemens.com/productcert/pdf/ssa-190839.pdf](https://cert-portal.siemens.com/productcert/pdf/ssa-190839.pdf)