CVE-2022-34465

CWE-125Out-of-bounds Read3 documents3 sources
Severity
7.8HIGH
EPSS
0.4%
top 38.16%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 12
Latest updateJul 13

Description

A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.250), Parasolid V34.1 (All versions < V34.1.233), Simcenter Femap V2022.1 (All versions < V2022.1.3), Simcenter Femap V2022.2 (All versions < V2022.2.2). The affected application contains an out of bounds read past the end of an allocated structure while parsing specially crafted NEU files. This could allow an attacker to execute code in the context of the current process. (ZD

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages7 packages

CVEListV5siemens/simcenter_femap_v2022.1All versions < V2022.1.3
CVEListV5siemens/simcenter_femap_v2022.2All versions < V2022.2.2
NVDsiemens/simcenter_femap2022.1.02022.1.3+1
NVDsiemens/parasolid33.133.1.264+2
CVEListV5siemens/parasolid_v33.1All versions < V33.1.264

Patches

🔴Vulnerability Details

2
GHSA
GHSA-c445-7759-935w: A vulnerability has been identified in Parasolid V332022-07-13
CVEList
CVE-2022-34465: A vulnerability has been identified in Parasolid V332022-07-12
CVE-2022-34465 (HIGH CVSS 7.8) | A vulnerability has been identified | cvebase.io