CVE-2023-49125

CWE-125Out-of-bounds Read3 documents3 sources
Severity
7.8HIGH
EPSS
0.0%
top 91.38%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedFeb 13

Description

A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.263), Parasolid V35.1 (All versions < V35.1.252), Parasolid V36.0 (All versions < V36.0.198), Solid Edge SE2023 (All versions < V223.0 Update 11), Solid Edge SE2024 (All versions < V224.0 Update 3). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted files containing XT format. This could allow an attacker to execute code in the context of the cu

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages8 packages

NVDsiemens/parasolid35.035.0.263+2
CVEListV5siemens/parasolid_v35.0< V35.0.263
CVEListV5siemens/parasolid_v35.1< V35.1.252
CVEListV5siemens/parasolid_v36.0< V36.0.198
CVEListV5siemens/solid_edge_se2023< V223.0 Update 11

🔴Vulnerability Details

2
GHSA
GHSA-v58f-qvrm-qqmh: A vulnerability has been identified in Parasolid V352024-02-13
CVEList
CVE-2023-49125: A vulnerability has been identified in Parasolid V352024-02-13
CVE-2023-49125 (HIGH CVSS 7.8) | A vulnerability has been identified | cvebase.io