CVE-2021-46699 – Siemens Simcenter Femap BDF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-46699
A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.1). Affected application contains a stack based buffer overflow vulnerability while parsing specially crafted BDF files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15061) Se ha identificado una vulnerabilidad en Simcenter Femap (Todas las versiones anteriores a V2022.1.1). La aplicación afectada contiene una vulnerabilidad de desbordamiento de búfer en la región stack de la memoria al analizar archivos BDF especialmente diseñados. • https://cert-portal.siemens.com/productcert/pdf/ssa-949188.pdf https://www.zerodayinitiative.com/advisories/ZDI-22-509 • CWE-121: Stack-based Buffer Overflow CWE-787: Out-of-bounds Write •
CVE-2021-46162 – Siemens Simcenter Femap NEU File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-46162
A vulnerability has been identified in Simcenter Femap (All versions < V2022.1.1). Affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted NEU files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15048) Se ha identificado una vulnerabilidad en Simcenter Femap (Todas las versiones anteriores a V2022.1.1). La aplicación afectada contiene una escritura fuera de límites más allá del final de una estructura asignada mientras analiza archivos NEU especialmente diseñados. • https://cert-portal.siemens.com/productcert/pdf/ssa-949188.pdf https://www.zerodayinitiative.com/advisories/ZDI-22-511 • CWE-787: Out-of-bounds Write •
CVE-2021-27387 – Siemens Simcenter Femap modfem File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-27387
A vulnerability has been identified in Simcenter Femap 2020.2 (All versions < V2020.2.MP3), Simcenter Femap 2021.1 (All versions < V2021.1.MP3). The femap.exe application lacks proper validation of user-supplied data when parsing FEMAP files. This could result in an out of bounds write past the end of an allocated structure, a different vulnerability than CVE-2021-27399. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12819) Se ha identificado una vulnerabilidad en Simcenter Femap versiones 2020.2 (Todas las versiones anteriores a V2020.2.MP3), Simcenter Femap versiones 2021.1 (Todas las versiones anteriores a V2021.1.MP3). • https://cert-portal.siemens.com/productcert/pdf/ssa-133038.pdf https://www.zerodayinitiative.com/advisories/ZDI-21-780 • CWE-787: Out-of-bounds Write •
CVE-2021-27399 – Siemens Simcenter Femap modfem File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2021-27399
A vulnerability has been identified in Simcenter Femap 2020.2 (All versions < V2020.2.MP3), Simcenter Femap 2021.1 (All versions < V2021.1.MP3). The femap.exe application lacks proper validation of user-supplied data when parsing FEMAP files. This could result in an out of bounds write past the end of an allocated structure, a different vulnerability than CVE-2021-27387. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12820) Se ha identificado una vulnerabilidad en Simcenter Femap versiones 2020.2 (Todas las versiones anteriores a V2020.2.MP3), Simcenter Femap versiones 2021.1 (Todas las versiones anteriores a V2021.1.MP3). • https://cert-portal.siemens.com/productcert/pdf/ssa-133038.pdf https://www.zerodayinitiative.com/advisories/ZDI-21-781 • CWE-787: Out-of-bounds Write •