CVE-2021-32944
published 2021-06-17CVE-2021-32944: A use-after-free issue exists in the DGN file-reading procedure in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation…
PriorityP341high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.67%
84.2th percentile
A use-after-free issue exists in the DGN file-reading procedure in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-supplied data. This can result in a memory corruption or arbitrary code execution, allowing attackers to cause a denial-of-service condition or execute code in the context of the current process.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opendesign | drawings_sdk | < 2022.4 | 2022.4 |
| opendesign | drawings_sdk | — | — |
| siemens | comos | < 10.4.1 | 10.4.1 |
| siemens | jt2go | < 13.2.0.1 | 13.2.0.1 |
| siemens | teamcenter_visualization | < 13.2.0.1 | 13.2.0.1 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens COMOS
cisa_ics·2022-03-10·CVSS 7.8
[HIGH] Siemens COMOS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens COMOS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: COMOS
- Vulnerabilities: Memory Allocation with Excessive Size Value, Untrusted Pointer Dereference, Type Confusion, Stack-based Buffer Overflow, Out-of-bounds Write, Out-of-bounds Read, Use After Free, Improper Check for Unusual or Exceptional Conditions
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may result in leaked information or remote code execution in the context of the cu
CISA ICS
Siemens JT2Go and Teamcenter Visualization products
cisa_ics·2021-08-10·CVSS 7.8
[HIGH] Siemens JT2Go and Teamcenter Visualization products
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens JT2Go and Teamcenter Visualization products
Last RevisedAugust 10, 2021
Alert CodeICSA-21-222-01
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: JT2Go & Teamcenter Visualization
- Vulnerabilities: Use After Free, Out-of-bounds Write, Out-of-bounds Read, NULL Pointer Dereference
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to crash an application or execute arbitrary code.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following Siemens products are aff
CISA ICS
Open Design Alliance Drawings SDK
cisa_ics·2021-06-08·CVSS 7.8
[HIGH] Open Design Alliance Drawings SDK
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Open Design Alliance Drawings SDK
Last RevisedJune 08, 2021
Alert CodeICSA-21-159-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Open Design Alliance
- Equipment: Drawings SDK
- Vulnerabilities: Out-of-bounds Read, Out-of-bounds Write, Improper check for Unusual or Exceptional Conditions, Use After Free
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow code execution in the context of the current process or cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The follo
GHSA
GHSA-vp45-9px8-7xw8: A use-after-free issue exists in the DGN file-reading procedure in the Drawings SDK (All versions prior to 2022
ghsa_unreviewed·2022-05-24
CVE-2021-32944 [HIGH] CWE-416 GHSA-vp45-9px8-7xw8: A use-after-free issue exists in the DGN file-reading procedure in the Drawings SDK (All versions prior to 2022
A use-after-free issue exists in the DGN file-reading procedure in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-supplied data. This can result in a memory corruption or arbitrary code execution, allowing attackers to cause a denial-of-service condition or execute code in the context of the current process.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-155599.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-365397.pdfhttps://us-cert.cisa.gov/ics/advisories/icsa-21-159-02https://www.zerodayinitiative.com/advisories/ZDI-21-987/https://www.zerodayinitiative.com/advisories/ZDI-21-990/https://cert-portal.siemens.com/productcert/pdf/ssa-155599.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-365397.pdfhttps://us-cert.cisa.gov/ics/advisories/icsa-21-159-02https://www.zerodayinitiative.com/advisories/ZDI-21-987/https://www.zerodayinitiative.com/advisories/ZDI-21-990/
2021-06-17
Published