CVE-2023-27404
published 2023-03-14CVE-2023-27404: A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application is vulnerable to stack-based buffer…
PriorityP343high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
2.71%
84.3th percentile
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application is vulnerable to stack-based buffer while parsing specially crafted SPP files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-20433)
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | tecnomatix_plant_simulation | < 2201.0006 | 2201.0006 |
| siemens | tecnomatix_plant_simulation | — | — |
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vendor_oracle9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-fjv6-xrfm-748r: A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201
ghsa_unreviewed·2023-03-14
CVE-2023-27404 [HIGH] CWE-121 GHSA-fjv6-xrfm-748r: A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201
A vulnerability has been identified in Tecnomatix Plant Simulation (All versions < V2201.0006). The affected application is vulnerable to stack-based buffer while parsing specially crafted SPP files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-20433)
Oracle
Oracle Oracle Supply Chain Risk Matrix: Security (FreeType) — CVE-2022-27404
vendor_oracle·2023-07-15·CVSS 9.8
CVE-2022-27404 [CRITICAL] Oracle Oracle Supply Chain Risk Matrix: Security (FreeType) — CVE-2022-27404
Oracle Oracle Supply Chain Risk Matrix: Security (FreeType) vulnerability
CVE: CVE-2022-27404
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2023 (JUL 2023)
Oracle
Oracle Oracle Construction and Engineering Risk Matrix: Document Viewing using Outside In technology (FreeType) — CVE-2022-27404
vendor_oracle·2023-04-15·CVSS 9.8
CVE-2022-27404 [CRITICAL] Oracle Oracle Construction and Engineering Risk Matrix: Document Viewing using Outside In technology (FreeType) — CVE-2022-27404
Oracle Oracle Construction and Engineering Risk Matrix: Document Viewing using Outside In technology (FreeType) vulnerability
CVE: CVE-2022-27404
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpuapr2023 (APR 2023)
Oracle
Oracle Oracle Communications Risk Matrix: Install/Upgrade (FreeType) — CVE-2022-27404
vendor_oracle·2023-01-15·CVSS 9.8
CVE-2022-27404 [CRITICAL] Oracle Oracle Communications Risk Matrix: Install/Upgrade (FreeType) — CVE-2022-27404
Oracle Oracle Communications Risk Matrix: Install/Upgrade (FreeType) vulnerability
CVE: CVE-2022-27404
CVSS: 9.8
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujan2023 (JAN 2023)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2023-03-14
Published