CVE-2022-3161
published 2023-01-13CVE-2022-3161: The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow an attacker to execute code in the context…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.41%
33.5th percentile
The APDFL.dll contains a memory corruption vulnerability while parsing
specially crafted PDF files. This could allow an attacker to execute
code in the context of the current process.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | jt2go | < 14.1.0.5 | 14.1.0.5 |
| siemens | teamcenter_visualization | >= 13.3.0 < 13.3.0.8 | 13.3.0.8 |
| siemens | teamcenter_visualization | >= 14.0 < 14.0.0.4 | 14.0.0.4 |
| siemens | teamcenter_visualization | >= 14.1 < 14.1.0.5 | 14.1.0.5 |
| siemens | teamcenter_visualization_v13.3 | < 13.3.0.8 | 13.3.0.8 |
| siemens | teamcenter_visualization_v14.0 | < 14.0.0.4 | 14.0.0.4 |
| siemens | teamcenter_visualization_v14.1 | < 14.1.0.5 | 14.1.0.5 |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h7rr-pq87-v2r8: The APDFL
ghsa_unreviewed·2023-01-13
CVE-2022-3161 [HIGH] CWE-119 GHSA-h7rr-pq87-v2r8: The APDFL
The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process.
CISA ICS
Siemens Teamcenter Visualization and JT2Go
cisa_ics·2022-12-15·CVSS 7.8
[HIGH] Siemens Teamcenter Visualization and JT2Go
## Archived Content In an effort to keep CISA.gov current, the archive contains outdated information that may not reflect current policy or programs.
ICS Advisory
##
Siemens Teamcenter Visualization and JT2Go
Last RevisedDecember 15, 2022
Alert CodeICSA-22-349-15
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: Teamcenter Visualization and JT2Go
- Vulnerabilities: Stack-based Buffer Overflow, Heap-based Buffer Overflow, Improper Restriction of Operations within the Bounds of a Memory Buffer
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could lead the application to crash or lead to arbitrary code execution.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
CISA
Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
cisa·2021-11-03·CVSS 9.8
CVE-2020-3161 [CRITICAL] CWE-20 Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Vulnerability: Cisco IP Phones Web Server Remote Code Execution and Denial-of-Service Vulnerability
Affected: Cisco Cisco IP Phones
Cisco IP Phones contain an improper input validation vulnerability for HTTP requests. Exploitation could allow an attacker to execute code remotely with root privileges or cause a denial-of-service (DoS) condition.
Required Action: Apply updates per vendor instructions.
Notes: https://nvd.nist.gov/vuln/detail/CVE-2020-3161
Remediation Due Date: 2022-05-03
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
https://cert-portal.siemens.com/productcert/csaf/ssa-360681.jsonhttps://cert-portal.siemens.com/productcert/html/ssa-360681.htmlhttps://www.cisa.gov/uscert/ics/advisories/icsa-22-349-15https://cert-portal.siemens.com/productcert/csaf/ssa-360681.jsonhttps://cert-portal.siemens.com/productcert/html/ssa-360681.htmlhttps://www.cisa.gov/uscert/ics/advisories/icsa-22-349-15
2023-01-13
Published