CVE-2021-25678
published 2021-04-22CVE-2021-25678: A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2020 (All versions < SE2020MP14), Solid Edge SE2021 (All…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
1.44%
70.1th percentile
A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2020 (All versions < SE2020MP14), Solid Edge SE2021 (All Versions < SE2021MP4). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12529)
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| redhat | ceph | >= 0 < 15.2.12-0ubuntu0.20.04.1 | 15.2.12-0ubuntu0.20.04.1 |
| siemens | solid_edge_se2020 | < se2020mp14 | se2020mp14 |
| siemens | solid_edge_se2020 | — | — |
| siemens | solid_edge_se2020 | — | — |
| siemens | solid_edge_se2021 | < se2021mp4 | se2021mp4 |
| siemens | solid_edge_se2021 | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
osv4.4MEDIUM
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens Solid Edge File Parsing (Update A)
cisa_ics·2021-04-13·CVSS 7.8
[HIGH] Siemens Solid Edge File Parsing (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Solid Edge File Parsing (Update A)
Last RevisedJune 08, 2021
Alert CodeICSA-21-103-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: Solid Edge
- Vulnerabilities: Out-of-bounds Write, Improper Restriction of XML External Entity Reference, Out-of-bounds Read
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-21-103-06 Siemens Solid Edge File Parsing that was published April 13, 2021, to the ICS webpage on us-cert.cisa.gov.
## 3. RISK EVALUATION
Successful explo
GHSA
GHSA-g3wc-226r-c28v: A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2020 (SE2020MP13), Solid Edge SE2021 (All Versions
ghsa_unreviewed·2022-05-24
CVE-2021-25678 [HIGH] CWE-787 GHSA-g3wc-226r-c28v: A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2020 (SE2020MP13), Solid Edge SE2021 (All Versions
A vulnerability has been identified in Solid Edge SE2020 (All versions < SE2020MP13), Solid Edge SE2020 (SE2020MP13), Solid Edge SE2021 (All Versions < SE2021MP4). Affected applications lack proper validation of user-supplied data when parsing PAR files. This could result in an out of bounds write past the end of an allocated structure. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12529)
OSV
ceph vulnerabilities
osv·2021-06-25·CVSS 4.4
CVE-2020-25678 ceph vulnerabilities
ceph vulnerabilities
It was discovered that in some situations Ceph logged passwords from the
mgr module in clear text. An attacker could use this to expose sensitive
information. (CVE-2020-25678)
Goutham Pacha Ravi, Jahson Babel, and John Garbutt discovered that user
credentials in Ceph could be manipulated in certain environments. An
attacker could use this to gain unintended access. (CVE-2020-27781)
It was discovered that the Ceph dashboard was susceptible to a cross-site
scripting attack. An attacker could use this to expose sensitive
information or gain unintended access. (CVE-2020-27839)
It was discovered that Ceph contained an authentication flaw, leading to
key reuse. An attacker could use this to cause a denial of service or
possibly impersonate another user. (CVE-2021-20288)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-04-22
Published