CVE-2021-33715
published 2021-07-13CVE-2021-33715: A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing specially crafted JT files, a race condition could cause an object…
PriorityP417medium5.5CVSS 3.1
AVLACLPRNUIRSUCNINAH
EPSS
0.24%
14.5th percentile
A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing specially crafted JT files, a race condition could cause an object to be released before being operated on, leading to NULL pointer deference condition and causing the application to crash. An attacker could leverage this vulnerability to cause a Denial-of-Service condition in the application.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | jt_utilities | < 13.0.2.0 | 13.0.2.0 |
| siemens | jt_utilities | — | — |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
nvdv2.02.1LOWAV:L/AC:L/Au:N/C:N/I:N/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA ICS
Siemens JT Utilities
cisa_ics·2021-07-13·CVSS 5.5
[MEDIUM] Siemens JT Utilities
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens JT Utilities
Last RevisedJuly 13, 2021
Alert CodeICSA-21-194-09
## 1. EXECUTIVE SUMMARY
- CVSS v3 5.5
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: JT Utilities
- Vulnerabilities: Function Call with Incorrect Variable or Reference as Argument, NULL Pointer Dereference
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could cause a denial-of-service condition.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Siemens JT Utilities are affected:
- All versions prior to v13.0.2.0
## 3.2 VULNERABILIT
GHSA
GHSA-3xx5-g4fv-w39v: A vulnerability has been identified in JT Utilities (All versions < V13
ghsa_unreviewed·2022-05-24
CVE-2021-33715 [MEDIUM] CWE-476 GHSA-3xx5-g4fv-w39v: A vulnerability has been identified in JT Utilities (All versions < V13
A vulnerability has been identified in JT Utilities (All versions < V13.0.2.0). When parsing specially crafted JT files, a race condition could cause an object to be released before being operated on, leading to NULL pointer deference condition and causing the application to crash. An attacker could leverage this vulnerability to cause a Denial-of-Service condition in the application.
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2021-07-13
Published