CVE-2023-30985Out-of-bounds Read in Siemens Solid Edge Se2023

CWE-125Out-of-bounds Read3 documents3 sources
Severity
5.5MEDIUMNVD
CNA3.3
EPSS
0.1%
top 71.37%
CISA KEV
Not in KEV
Exploit
No known exploits
Affected products
Timeline
PublishedMay 9

Description

A vulnerability has been identified in Solid Edge SE2023 (All versions < V223.0 Update 3), Solid Edge SE2023 (All versions < V223.0 Update 2). Affected applications contain an out of bounds read past the end of an allocated buffer while parsing a specially crafted OBJ file. This vulnerability could allow an attacker to disclose sensitive information. (ZDI-CAN-19426)

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5siemens/solid_edge_se2023All versions < V223.0 Update 2, All versions < V223.0 Update 3+1
NVDsiemens/solid_edge_se2023update_0001

🔴Vulnerability Details

2
GHSA
GHSA-r26h-mc72-92q2: A vulnerability has been identified in Solid Edge SE2023 (All versions < VX2023-05-09
CVEList
CVE-2023-30985: A vulnerability has been identified in Solid Edge SE2023 (All versions < V2232023-05-09
CVE-2023-30985 — Out-of-bounds Read in Siemens | cvebase