CVE-2021-44014
HIGH
7,8
Source: [email protected]
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high
MEDIUM
6,8
Source: [email protected]
Access Vector: network
Access Complexity: medium
Authentication: none
Confidentiality: partial
Integrity: partial
Availability: partial
Description
AI Translation Available
A vulnerability has been identified in JT Open (All versions < V11.1.1.0), JT Utilities (All versions < V13.1.1.0), Solid Edge (All versions < V2023). The Jt1001.dll contains a use-after-free vulnerability that could be triggered while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-15057, ZDI-CAN-19081)
EPSS (Exploit Prediction Scoring System)
Trend Analysis
EPSS (Exploit Prediction Scoring System)
Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.
EPSS Score
0,0093
Percentile
0,8th
Updated
EPSS Score Trend (Last 90 Days)
416
Use After Free
StableCommon Consequences
Security Scopes Affected:
Integrity
Availability
Confidentiality
Potential Impacts:
Modify Memory
Dos: Crash, Exit, Or Restart
Execute Unauthorized Code Or Commands
Applicable Platforms
Languages:
C, C++, Memory-Unsafe
Application
Jt2Go by Siemens
Version Range Affected
To
13.2.0.5
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Teamcenter Visualization by Siemens
Version Range Affected
To
13.2.0.5
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Jt Open Toolkit by Siemens
Version Range Affected
To
11.1.1.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:siemens:jt_open_toolkit:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Jt Utilities by Siemens
Version Range Affected
To
13.1.1.0
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:siemens:jt_utilities:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application
Solid Edge by Siemens
Version Range Affected
To
se2023
(exclusive)
CPE Identifier
View Detailed Analysis
cpe:2.3:a:siemens:solid_edge:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://cert-portal.siemens.com/productcert/pdf/ssa-595101.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-936212.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-595101.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-936212.pdf