CVE-2021-32946
published 2021-06-17CVE-2021-32946: An improper check for unusual or exceptional conditions issue exists within the parsing DGN files from Drawings SDK (Version 2022.4 and prior) resulting from…
PriorityP339high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.80%
84.9th percentile
An improper check for unusual or exceptional conditions issue exists within the parsing DGN files from Drawings SDK (Version 2022.4 and prior) resulting from the lack of proper validation of the user-supplied data. This may result in several of out-of-bounds problems and allow attackers to cause a denial-of-service condition or execute code in the context of the current process.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| opendesign | drawings_sdk | <= 2022.4 | — |
| opendesign | drawings_sdk | — | — |
| siemens | comos | < 10.4.1 | 10.4.1 |
| siemens | jt2go | < 13.2.0.2 | 13.2.0.2 |
| siemens | teamcenter_visualization | < 13.2.0.2 | 13.2.0.2 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens COMOS
cisa_ics·2022-03-10·CVSS 7.8
[HIGH] Siemens COMOS
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens COMOS
Last RevisedMarch 10, 2022
Alert CodeICSA-22-069-06
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: COMOS
- Vulnerabilities: Memory Allocation with Excessive Size Value, Untrusted Pointer Dereference, Type Confusion, Stack-based Buffer Overflow, Out-of-bounds Write, Out-of-bounds Read, Use After Free, Improper Check for Unusual or Exceptional Conditions
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may result in leaked information or remote code execution in the context of the cu
CISA ICS
Siemens JT2Go and Teamcenter Visualization (Update A)
cisa_ics·2021-08-10·CVSS 7.8
[HIGH] Siemens JT2Go and Teamcenter Visualization (Update A)
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens JT2Go and Teamcenter Visualization (Update A)
Last RevisedSeptember 14, 2021
Alert CodeICSA-21-222-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: JT2Go & Teamcenter Visualization
- Vulnerabilities: Improper Check for Unusual or Exceptional Conditions, Out-of-bounds Write, Out-of-bounds Read
## 2. UPDATE INFORMATION
This updated advisory is a follow-up to the original advisory titled ICSA-21-222-03 Siemens JT2Go and Teamcenter Visualization that was published August 10, 2021, to the ICS webpage on us-cert.c
CISA ICS
Open Design Alliance Drawings SDK
cisa_ics·2021-06-08·CVSS 7.8
[HIGH] Open Design Alliance Drawings SDK
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Open Design Alliance Drawings SDK
Last RevisedJune 08, 2021
Alert CodeICSA-21-159-02
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Open Design Alliance
- Equipment: Drawings SDK
- Vulnerabilities: Out-of-bounds Read, Out-of-bounds Write, Improper check for Unusual or Exceptional Conditions, Use After Free
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities may allow code execution in the context of the current process or cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The follo
GHSA
GHSA-cv5v-qfpj-5pm3: An improper check for unusual or exceptional conditions issue exists within the parsing DGN files from Drawings SDK (Version 2022
ghsa_unreviewed·2022-05-24
CVE-2021-32946 [HIGH] CWE-754 GHSA-cv5v-qfpj-5pm3: An improper check for unusual or exceptional conditions issue exists within the parsing DGN files from Drawings SDK (Version 2022
An improper check for unusual or exceptional conditions issue exists within the parsing DGN files from Drawings SDK (Version 2022.4 and prior) resulting from the lack of proper validation of the user-supplied data. This may result in several of out-of-bounds problems and allow attackers to cause a denial-of-service condition or execute code in the context of the current process.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/pdf/ssa-155599.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-938030.pdfhttps://us-cert.cisa.gov/ics/advisories/icsa-21-159-02https://www.zerodayinitiative.com/advisories/ZDI-21-983/https://www.zerodayinitiative.com/advisories/ZDI-21-985/https://cert-portal.siemens.com/productcert/pdf/ssa-155599.pdfhttps://cert-portal.siemens.com/productcert/pdf/ssa-938030.pdfhttps://us-cert.cisa.gov/ics/advisories/icsa-21-159-02https://www.zerodayinitiative.com/advisories/ZDI-21-983/https://www.zerodayinitiative.com/advisories/ZDI-21-985/
2021-06-17
Published