- Description
- A vulnerability has been identified in JT2Go (All versions < V14.3.0.6), Teamcenter Visualization V13.3 (All versions < V13.3.0.13), Teamcenter Visualization V14.1 (All versions < V14.1.0.12), Teamcenter Visualization V14.2 (All versions < V14.2.0.9), Teamcenter Visualization V14.3 (All versions < V14.3.0.6). The affected applications contain a stack overflow vulnerability while parsing specially crafted CGM files. This could allow an attacker to execute code in the context of the current process.
- Source
- productcert@siemens.com
- NVD status
- Modified
CVSS 3.1
- Type
- Primary
- Base score
- 7.8
- Impact score
- 5.9
- Exploitability score
- 1.8
- Vector string
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Severity
- HIGH
- productcert@siemens.com
- CWE-121
- Hype score
- Not currently trending
[
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "46A0DA84-3D17-4B66-8D2A-F3508436032C",
"versionEndExcluding": "14.3.0.6"
},
{
"criteria": "cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "AD077F2B-E8A3-4766-91C4-BA42747301BD",
"versionEndExcluding": "13.3.0.13",
"versionStartIncluding": "13.3.0"
},
{
"criteria": "cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E256021C-A93A-4D2C-B3BA-6A26F1735418",
"versionEndExcluding": "14.1.0.12",
"versionStartIncluding": "14.1"
},
{
"criteria": "cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "69855C2B-0F94-45CE-A7DD-D87A4E4C608C",
"versionEndExcluding": "14.2.0.9",
"versionStartIncluding": "14.2"
},
{
"criteria": "cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "E21BB537-ED57-4F27-B9C9-1E5816F2F294",
"versionEndExcluding": "14.3.0.6",
"versionStartIncluding": "14.3"
}
],
"operator": "OR"
}
]
}
]