CVE-2023-49125
published 2024-02-13CVE-2023-49125: A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.263), Parasolid V35.1 (All versions < V35.1.252), Parasolid V36.0 (All versions <…
PriorityP340high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
EPSS
0.20%
9.8th percentile
A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.263), Parasolid V35.1 (All versions < V35.1.252), Parasolid V36.0 (All versions < V36.0.198), Solid Edge SE2023 (All versions < V223.0 Update 11), Solid Edge SE2024 (All versions < V224.0 Update 3). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted files containing XT format. This could allow an attacker to execute code in the context of the current process.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| siemens | parasolid | >= 35.0 < 35.0.263 | 35.0.263 |
| siemens | parasolid | >= 35.1 < 35.1.252 | 35.1.252 |
| siemens | parasolid | >= 36.0 < 36.0.198 | 36.0.198 |
| siemens | parasolid_v35.0 | < V35.0.263 | V35.0.263 |
| siemens | parasolid_v35.1 | < V35.1.252 | V35.1.252 |
| siemens | parasolid_v36.0 | < V36.0.198 | V36.0.198 |
| siemens | solid_edge_se2023 | < V223.0 Update 11 | V223.0 Update 11 |
| siemens | solid_edge_se2023 | < 223.0 | 223.0 |
| siemens | solid_edge_se2023 | — | — |
| siemens | solid_edge_se2024 | < V224.0 Update 3 | V224.0 Update 3 |
| siemens | solid_edge_se2024 | < 224.0 | 224.0 |
| siemens | solid_edge_se2024 | — | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-v58f-qvrm-qqmh: A vulnerability has been identified in Parasolid V35
ghsa_unreviewed·2024-02-13
CVE-2023-49125 [HIGH] CWE-125 GHSA-v58f-qvrm-qqmh: A vulnerability has been identified in Parasolid V35
A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.263), Parasolid V35.1 (All versions < V35.1.252), Parasolid V36.0 (All versions < V36.0.198). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted files containing XT format. This could allow an attacker to execute code in the context of the current process.
CISA ICS
Siemens Solid Edge
cisa_ics·2024-03-14·CVSS 7.8
[HIGH] Siemens Solid Edge
ICS Advisory
##
Siemens Solid Edge
Release DateMarch 14, 2024
Alert CodeICSA-24-074-02
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 7.3
- ATTENTION: Low Attack Complexity
- Vendor: Siemens
- Equipment: Solid Edge
- Vulnerability: Out-of-bounds Read
## 2. RISK EVALUATION
Successful exploitation of this vulnerability could allow an attacker to cause an out-of-bounds read past the end of an allocated structure while parsing specially crafted files, r
CISA ICS
Siemens Parasolid
cisa_ics·2024-02-15·CVSS 7.8
[HIGH] Siemens Parasolid
ICS Advisory
##
Siemens Parasolid
Release DateFebruary 15, 2024
Alert CodeICSA-24-046-13
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v3 7.8
- ATTENTION: Low Attack Complexity
- Vendor: Siemens
- Equipment: Parasolid
- Vulnerabilities: Out-of-bounds Read, NULL Pointer Dereference
## 2. RISK EVALUATION
Successful exploitation of these vulnerabilities could allow an attacker to leverage the vulnerability to perform remote code execution in the context
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-02-13
Published