CVE-2022-46345

Published: Dic 13, 2022 Last Modified: Nov 21, 2024 EU-VD ID: EUVD-2022-49161 Aliases: GSD-2022-46345
ExploitDB:
Other exploit source:
Google Dorks:
HIGH 7,8
Attack Vector: local
Attack Complexity: low
Privileges Required: none
User Interaction: required
Scope: unchanged
Confidentiality: high
Integrity: high
Availability: high

Description

AI Translation Available

A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170), Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2022 (All versions), Solid Edge SE2023 (All versions < V223.0Update2). The affected applications contain an out of bounds write past the end of an allocated structure while parsing specially crafted X_B files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-19070)

EPSS (Exploit Prediction Scoring System)

Trend Analysis

EPSS (Exploit Prediction Scoring System)

Prevede la probabilità di sfruttamento basata su intelligence sulle minacce e sulle caratteristiche della vulnerabilità.

EPSS Score
0,0011
Percentile
0,3th
Updated

EPSS Score Trend (Last 90 Days)

787

Out-of-bounds Write

Draft
Common Consequences
Security Scopes Affected:
Integrity Availability Other
Potential Impacts:
Modify Memory Execute Unauthorized Code Or Commands Dos: Crash, Exit, Or Restart Unexpected State
Applicable Platforms
Languages: Assembly, C, C++, Memory-Unsafe
Technologies: ICS/OT
View CWE Details
Application

Parasolid by Siemens

Version Range Affected
From 34.1 (inclusive)
To 34.1.242 (exclusive)
cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Solid Edge Se2023 by Siemens

cpe:2.3:a:siemens:solid_edge_se2023:-:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Solid Edge Se2022 by Siemens

cpe:2.3:a:siemens:solid_edge_se2022:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Solid Edge Se2023 by Siemens

cpe:2.3:a:siemens:solid_edge_se2023:223.0:-:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Parasolid by Siemens

Version Range Affected
From 35.0 (inclusive)
To 35.0.170 (exclusive)
cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Parasolid by Siemens

Version Range Affected
From 34.0 (inclusive)
To 34.0.252 (exclusive)
cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
Application

Parasolid by Siemens

Version Range Affected
From 33.1 (inclusive)
To 33.1.264 (exclusive)
cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:*
Common Platform Enumeration - Standardized vulnerability identification
https://cert-portal.siemens.com/productcert/pdf/ssa-491245.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-588101.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-491245.pdf
https://cert-portal.siemens.com/productcert/pdf/ssa-588101.pdf