CVE-2021-37203

CWE-125Out-of-bounds Read3 documents3 sources
Severity
7.1HIGH
EPSS
0.2%
top 59.28%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 14
Latest updateMay 24

Description

A vulnerability has been identified in NX 1980 Series (All versions < V1984), Solid Edge SE2021 (All versions < SE2021MP8). The plmxmlAdapterIFC.dll contains an out-of-bounds read while parsing user supplied IFC files which could result in a read past the end of an allocated buffer. This could allow an attacker to cause a denial-of-service condition or read sensitive information from memory locations.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:HExploitability: 1.8 | Impact: 5.2

Affected Packages4 packages

CVEListV5siemens/solid_edge_se2021All versions < SE2021MP8
NVDsiemens/solid_edge< se2021+1
CVEListV5siemens/nx_1980_seriesAll versions < V1984
NVDsiemens/nx_1980< 1984

Patches

🔴Vulnerability Details

2
GHSA
GHSA-98jw-m4q8-f849: A vulnerability has been identified in NX 1980 Series (All versions < V1984)2022-05-24
CVEList
CVE-2021-37203: A vulnerability has been identified in NX 1980 Series (All versions < V1984), Solid Edge SE2021 (All versions < SE2021MP8)2021-09-14
CVE-2021-37203 (HIGH CVSS 7.1) | A vulnerability has been identified | cvebase.io