CVE-2021-27040
published 2021-06-25CVE-2021-27040: A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute…
PriorityP419low3.3CVSS 3.1
AVLACLPRNUIRSUCLINAN
EPSS
2.74%
84.4th percentile
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
Affected
43 ranges· showing 25
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| autodesk | advance_steel | >= 2019 < 2019.1.3 | 2019.1.3 |
| autodesk | advance_steel | >= 2020 < 2020.1.4 | 2020.1.4 |
| autodesk | advance_steel | >= 2021 < 2021.1.1 | 2021.1.1 |
| autodesk | advance_steel | >= 2022 < 2022.0.1 | 2022.0.1 |
| autodesk | autocad | >= 2019 < 2019.1.3 | 2019.1.3 |
| autodesk | autocad | >= 2020 < 2020.1.4 | 2020.1.4 |
| autodesk | autocad | >= 2021 < 2021.1.1 | 2021.1.1 |
| autodesk | autocad | >= 2022 < 2022.0.1 | 2022.0.1 |
| autodesk | autocad_architecture | >= 2019 < 2019.1.3 | 2019.1.3 |
| autodesk | autocad_architecture | >= 2020 < 2020.1.4 | 2020.1.4 |
| autodesk | autocad_architecture | >= 2021 < 2021.1.1 | 2021.1.1 |
| autodesk | autocad_architecture | 2022 – 2022.0.1 | — |
| autodesk | autocad_electrical | >= 2019 < 2019.1.3 | 2019.1.3 |
| autodesk | autocad_electrical | >= 2020 < 2020.1.4 | 2020.1.4 |
| autodesk | autocad_electrical | >= 2021 < 2021.1.1 | 2021.1.1 |
| autodesk | autocad_electrical | >= 2022 < 2022.0.1 | 2022.0.1 |
| autodesk | autocad_lt | >= 2019 < 2019.1.3 | 2019.1.3 |
| autodesk | autocad_lt | >= 2020 < 2020.1.4 | 2020.1.4 |
| autodesk | autocad_lt | >= 2021 < 2021.1.1 | 2021.1.1 |
| autodesk | autocad_lt | >= 2022 < 2022.0.1 | 2022.0.1 |
| autodesk | autocad_map_3d | >= 2019 < 2019.1.3 | 2019.1.3 |
| autodesk | autocad_map_3d | >= 2020 < 2020.1.4 | 2020.1.4 |
| autodesk | autocad_map_3d | >= 2021 < 2021.1.1 | 2021.1.1 |
| autodesk | autocad_map_3d | >= 2022 < 2022.0.1 | 2022.0.1 |
| autodesk | autocad_mechanical | >= 2019 < 2019.1.3 | 2019.1.3 |
CVSS provenance
nvdv3.13.3LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-qxw7-h89m-x9wf: A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file
ghsa_unreviewed·2022-05-24
CVE-2021-27040 [HIGH] CWE-125 GHSA-qxw7-h89m-x9wf: A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file
A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.
CISA ICS
ICONICS GENESIS64 and Mitsubishi Electric MC Works64
cisa_ics·2021-10-21·CVSS 3.3
[LOW] ICONICS GENESIS64 and Mitsubishi Electric MC Works64
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
ICONICS GENESIS64 and Mitsubishi Electric MC Works64
Last RevisedOctober 21, 2021
Alert CodeICSA-21-294-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: ICONICS, Mitsubishi Electric
- Equipment: ICONICS GENESIS64, Mitsubishi Electric MC Works64
- Vulnerabilities: Out-of-bounds Read, Out-of-bounds Write
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may result in remote code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The vulnerabilities affect the following HMI SCADA products:
- GENESIS64 (all
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004https://www.zerodayinitiative.com/advisories/ZDI-21-1236/https://www.zerodayinitiative.com/advisories/ZDI-21-1238/https://www.zerodayinitiative.com/advisories/ZDI-22-378/https://www.zerodayinitiative.com/advisories/ZDI-22-473/https://www.autodesk.com/trust/security-advisories/adsk-sa-2021-0004https://www.zerodayinitiative.com/advisories/ZDI-21-1236/https://www.zerodayinitiative.com/advisories/ZDI-21-1238/https://www.zerodayinitiative.com/advisories/ZDI-22-378/https://www.zerodayinitiative.com/advisories/ZDI-22-473/
2021-06-25
Published