CVE-2022-37864
published 2022-10-11CVE-2022-37864: A vulnerability has been identified in Solid Edge (All Versions < SE2022MP9). The affected application contains an out of bounds write past the fixed-length…
PriorityP338high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.22%
12.8th percentile
A vulnerability has been identified in Solid Edge (All Versions < SE2022MP9). The affected application contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted DWG files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-17627)
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | solid_edge | — | — |
| siemens | solid_edge | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-2wrq-r74m-9pj3: A vulnerability has been identified in Solid Edge (All Versions < SE2022MP9)
ghsa_unreviewed·2022-10-11
CVE-2022-37864 [HIGH] CWE-122 GHSA-2wrq-r74m-9pj3: A vulnerability has been identified in Solid Edge (All Versions < SE2022MP9)
A vulnerability has been identified in Solid Edge (All Versions < SE2022MP9). The affected application contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted DWG files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-17627)
CISA ICS
Siemens Solid Edge
cisa_ics·2023-01-31·CVSS 7.8
[HIGH] Siemens Solid Edge
ICS Advisory
##
Siemens Solid Edge
Last RevisedJanuary 31, 2023
Alert CodeICSA-22-286-03
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low attack complexity
- Vendor: Siemens
- Equipment: Solid Edge
- Vulnerability: Heap-based Buffer Overflow
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to execute arbitrary code in the current process.
## 3. TECHNICAL DETAILS
## 3.1 AFFECTED PRODUCTS
The following versions of Siemens Solid Edge, a portfolio of software tools, are affected:
- Solid Edge: all versions prior to SE2022MP9
## 3.2 VULNERABILITY OVERVIEW
## 3.2.1 HEAP-BASED BUFFER OVERFLOW CWE-122
Siemens Solid Edge, versions prior to SE2022MP9, contains an out-of-bounds write past the fixed-length heap-ba
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-10-11
Published