cbcvebase.
CVE-2021-25173
published 2021-01-18

CVE-2021-25173: An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading…

high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
An issue was discovered in Open Design Alliance Drawings SDK before 2021.12. A memory allocation with excessive size vulnerability exists when reading malformed DGN files, which allows attackers to cause a crash, potentially enabling denial of service (crash, exit, or restart).

Affected

4 ranges
VendorProductVersion rangeFixed in
opendesigndrawings_software_development_kit< 2021.122021.12
siemenscomos< 10.4.110.4.1
siemensjt2go< 13.1.0.113.1.0.1
siemensteamcenter_visualization< 13.1.0.113.1.0.1