CVE-2023-30795
https://notcve.org/view.php?id=CVE-2023-30795
A vulnerability has been identified in JT Open (All versions < V11.4), JT Utilities (All versions < V13.4), Parasolid V34.0 (All versions < V34.0.253), Parasolid V34.1 (All versions < V34.1.243), Parasolid V35.0 (All versions < V35.0.177), Parasolid V35.1 (All versions < V35.1.073). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. Se ha identificado una vulnerabilidad en JT Open (Todas las versiones inferiores a V11.4), JT Utilities (Todas las versiones inferiores a V13.4), Parasolid V34.0 (Todas las versiones inferiores a V34.0.253), Parasolid V34.1 (Todas las versiones inferiores a V34.1.243), Parasolid V35.0 (Todas las versiones inferiores a V35.0.177), Parasolid V35.1 (Todas las versiones inferiores a V35.1.073). Las aplicaciones afectadas contienen una lectura fuera de límites más allá del final de una estructura asignada al analizar archivos JT especialmente diseñados. • https://cert-portal.siemens.com/productcert/pdf/ssa-001569.pdf • CWE-125: Out-of-bounds Read •
CVE-2023-25140
https://notcve.org/view.php?id=CVE-2023-25140
A vulnerability has been identified in Parasolid V34.0 (All versions < V34.0.254), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170), Parasolid V35.1 (All versions < V35.1.150), Solid Edge SE2022 (All versions < V222.0MP12). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process. • https://cert-portal.siemens.com/productcert/pdf/ssa-491245.pdf https://cert-portal.siemens.com/productcert/pdf/ssa-836777.pdf • CWE-125: Out-of-bounds Read •
CVE-2022-47936
https://notcve.org/view.php?id=CVE-2022-47936
A vulnerability has been identified in JT Open (All versions < V11.2.3.0), JT Utilities (All versions < V13.2.3.0), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170), Parasolid V35.1 (All versions < V35.1.150). The affected application contains a stack overflow vulnerability while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process. • https://cert-portal.siemens.com/productcert/pdf/ssa-836777.pdf • CWE-121: Stack-based Buffer Overflow •
CVE-2022-46347 – Siemens Solid Edge Viewer X_B File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-46347
A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170), Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2). The affected applications contain an out of bounds write past the end of an allocated structure while parsing specially crafted X_B files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19079) Se ha identificado una vulnerabilidad en: Parasolid V33.1 (Todas las versiones < V33.1.264), Parasolid V34.0 (Todas las versiones < V34.0.252), Parasolid V34.1 (Todas las versiones < V34.1.242), Parasolid V35 .0 (Todas las versiones < V35.0.170), Solid Edge SE2022 (Todas las versiones < V222.0MP12), Solid Edge SE2022 (Todas las versiones), Solid Edge SE2023 (Todas las versiones < V223.0Update2). Las aplicaciones afectadas contienen una escritura fuera de los límites más allá del final de una estructura asignada mientras analizan archivos X_B especialmente manipulados. Esto podría permitir a un atacante ejecutar código en el contexto del proceso actual. • https://cert-portal.siemens.com/productcert/pdf/ssa-491245.pdf https://cert-portal.siemens.com/productcert/pdf/ssa-588101.pdf • CWE-787: Out-of-bounds Write •
CVE-2022-46345 – Siemens Solid Edge Viewer X_B File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
https://notcve.org/view.php?id=CVE-2022-46345
A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170), Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2). The affected applications contain an out of bounds write past the end of an allocated structure while parsing specially crafted X_B files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19070) Se ha identificado una vulnerabilidad en: Parasolid V33.1 (Todas las versiones < V33.1.264), Parasolid V34.0 (Todas las versiones < V34.0.252), Parasolid V34.1 (Todas las versiones < V34.1.242), Parasolid V35 .0 (Todas las versiones < V35.0.170), Solid Edge SE2022 (Todas las versiones < V222.0MP12), Solid Edge SE2022 (Todas las versiones), Solid Edge SE2023 (Todas las versiones < V223.0Update2). Las aplicaciones afectadas contienen una escritura fuera de los límites más allá del final de una estructura asignada mientras analizan archivos X_B especialmente manipulados. Esto podría permitir a un atacante ejecutar código en el contexto del proceso actual. • https://cert-portal.siemens.com/productcert/pdf/ssa-491245.pdf https://cert-portal.siemens.com/productcert/pdf/ssa-588101.pdf • CWE-787: Out-of-bounds Write •