CVE-2022-24290Stack-based Buffer Overflow in Siemens Teamcenter

Severity
7.5HIGHNVD
EPSS
0.7%
top 28.62%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 20
Latest updateMay 21

Description

A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.13), Teamcenter V13.0 (All versions < V13.0.0.9), Teamcenter V13.1 (All versions), Teamcenter V13.2 (All versions < V13.2.0.8), Teamcenter V13.3 (All versions < V13.3.0.3), Teamcenter V14.0 (All versions < V14.0.0.2). The tcserver.exe binary in affected applications is vulnerable to a stack overflow condition during the parsing of user input that may lead the binary to crash.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:HExploitability: 3.9 | Impact: 3.6

Affected Packages7 packages

NVDsiemens/teamcenter12.412.4.0.13+5
CVEListV5siemens/teamcenter_v12.4All versions < V12.4.0.13
CVEListV5siemens/teamcenter_v13.0All versions < V13.0.0.9
CVEListV5siemens/teamcenter_v13.1All versions
CVEListV5siemens/teamcenter_v13.2All versions < V13.2.0.8

Patches

🔴Vulnerability Details

2
GHSA
GHSA-5cpx-m8gp-jj7j: A vulnerability has been identified in Teamcenter V122022-05-21
CVEList
CVE-2022-24290: A vulnerability has been identified in Teamcenter V122022-05-10
CVE-2022-24290 — Stack-based Buffer Overflow in Siemens | cvebase