CVE-2021-25173
published 2021-01-18CVE-2021-25173: An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading…
PriorityP433high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.29%
81.2th percentile
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading malformed DGN files, which allows attackers to cause a crash, potentially enabling denial of service (crash, exit, or restart).
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opendesign | drawings_software_development_kit | < 2021.12 | 2021.12 |
| siemens | comos | < 10.4.1 | 10.4.1 |
| siemens | jt2go | < 13.1.0.1 | 13.1.0.1 |
| siemens | teamcenter_visualization | < 13.1.0.1 | 13.1.0.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens COMOS
cisa_ics·2022-03-10·CVSS 7.8
[HIGH] Siemens COMOS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens COMOS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: COMOS
- Vulnerabilities: Memory Allocation with Excessive Size Value, Untrusted Pointer Dereference, Type Confusion, Stack-based Buffer Overflow, Out-of-bounds Write, Out-of-bounds Read, Use After Free, Improper Check for Unusual or Exceptional Conditions
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may result in leaked information or remote code execution in the context of the cu
CISA ICS
Open Design Alliance Drawings SDK (Update A)
cisa_ics·2021-02-16·CVSS 7.8
[HIGH] Open Design Alliance Drawings SDK (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Open Design Alliance Drawings SDK (Update A)
Last RevisedMay 06, 2021
Alert CodeICSA-21-047-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Open Design Alliance
- Equipment: Drawings SDK
--------- Begin Update A Part 1 of 3 ---------
- Vulnerabilities: Stack-based Buffer Overflow, Type Confusion, Untrusted Pointer Dereference, Incorrect Type Conversion or Cast, Memory Allocation with Excessive Size Value, Out of Bounds Write
--------- End Update A Part 1 of 3 ---------
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to
CISA ICS
Siemens JT2Go and Teamcenter Visualization (Update A)
cisa_ics·2021-02-09·CVSS 7.8
[HIGH] Siemens JT2Go and Teamcenter Visualization (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens JT2Go and Teamcenter Visualization (Update A)
Last RevisedMay 27, 2021
Alert CodeICSA-21-040-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: JT2Go and Teamcenter Visualization
- Vulnerabilities: Out-of-bounds Read, Improper Restriction of Operations within the Bounds of a Memory Buffer, Stack-based Buffer overflow, Out-of-Bounds Write, Type Confusion, Untrusted Pointer Dereference, Incorrect Type Conversion or Cast
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled
GHSA
GHSA-89c6-8x2j-h6xj: An issue was discovered in Open Design Alliance Drawings SDK before 2021
ghsa_unreviewed·2022-05-24
CVE-2021-25173 [HIGH] CWE-770 GHSA-89c6-8x2j-h6xj: An issue was discovered in Open Design Alliance Drawings SDK before 2021
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading malformed DGN files, which allows attackers to cause a crash, potentially enabling denial of service (crash, exit, or restart).
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-155599.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-663999.pdfhttps://www.opendesign.com/security-advisorieshttps://www.zerodayinitiative.com/advisories/ZDI-21-225/https://cert-portal.siemens.com/productcert/pdf/ssa-155599.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-663999.pdfhttps://www.opendesign.com/security-advisorieshttps://www.zerodayinitiative.com/advisories/ZDI-21-225/
2021-01-18
Published