CVE-2021-37176Out-of-bounds Read in Siemens Simcenter Femap V2020.2

CWE-125Out-of-bounds Read3 documents3 sources
Severity
3.3LOWNVD
EPSS
0.2%
top 62.10%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 14
Latest updateMay 24

Description

A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). The femap.exe application lacks proper validation of user-supplied data when parsing modfem files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-14260)

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages3 packages

CVEListV5siemens/simcenter_femap_v2020.2All versions
CVEListV5siemens/simcenter_femap_v2021.1All versions
NVDsiemens/simcenter_femap2020.2, 2021.1+1

Patches

🔴Vulnerability Details

2
GHSA
GHSA-62mh-7jc4-wf35: A vulnerability has been identified in Simcenter Femap V20202022-05-24
CVEList
CVE-2021-37176: A vulnerability has been identified in Simcenter Femap V20202021-09-14
CVE-2021-37176 — Out-of-bounds Read in Siemens | cvebase