CVE-2021-46151Out-of-bounds Write in Siemens Simcenter Femap V2020.2

Severity
7.8HIGHNVD
EPSS
0.3%
top 43.06%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 9
Latest updateFeb 10

Description

A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted NEU files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-14754, ZDI-CAN-15082)

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages3 packages

CVEListV5siemens/simcenter_femap_v2020.2All versions
CVEListV5siemens/simcenter_femap_v2021.1All versions
NVDsiemens/simcenter_femap2020.2, 2021.1+1

🔴Vulnerability Details

2
GHSA
GHSA-w53j-mr4p-h52p: A vulnerability has been identified in Simcenter Femap V20202022-02-10
CVEList
CVE-2021-46151: A vulnerability has been identified in Simcenter Femap V20202022-02-09
CVE-2021-46151 — Out-of-bounds Write in Siemens | cvebase