ZDI-CAN-19561: ZDI-23-1023: Siemens Solid Edge Viewer STP File Parsing Memory Corruption Remote Code Execution Vulnerability
Published Aug 4, 2023
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Siemens Solid Edge Viewer. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
1 affected component
Siemens Solid Edge Viewer
Event History
Aug 4, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19561?
ZDI-CAN-19561 is classified as a critical vulnerability due to its potential to allow remote code execution.
2
How do I fix ZDI-CAN-19561?
To fix ZDI-CAN-19561, update the Siemens Solid Edge Viewer to the latest version provided by Siemens.
3
What are the effects of ZDI-CAN-19561 if exploited?
If exploited, ZDI-CAN-19561 can allow attackers to execute arbitrary code on the affected system.
4
Is user interaction required to exploit ZDI-CAN-19561?
Yes, user interaction is required as the target must visit a malicious page or open a malicious file.
5
Which software is affected by ZDI-CAN-19561?
ZDI-CAN-19561 affects installations of Siemens Solid Edge Viewer.