Description
A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.1), Tecnomatix Plant Simulation V2201 (All versions < V2201.0010), Tecnomatix Plant Simulation V2302 (All versions < V2302.0004). The affected application contains a type confusion vulnerability while parsing WRL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20826)
CVSS breakdown
CVSS 3.1
Attack Vector
Local
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
High
E
Physical
RL
O
RC
Changed
Affected products
- Siemens / JT2GoAll versions < V14.3.0.1 – All versions < V14.3.0.1
- Siemens / Teamcenter Visualization V13.3All versions < V13.3.0.12 – All versions < V13.3.0.12
- Siemens / Teamcenter Visualization V14.0All versions – All versions
- Siemens / Teamcenter Visualization V14.1All versions < V14.1.0.11 – All versions < V14.1.0.11
- Siemens / Teamcenter Visualization V14.2All versions < V14.2.0.6 – All versions < V14.2.0.6
- Siemens / Teamcenter Visualization V14.3All versions < V14.3.0.1 – All versions < V14.3.0.1
- Siemens / Tecnomatix Plant Simulation V2201All versions < V2201.0010 – All versions < V2201.0010
- Siemens / Tecnomatix Plant Simulation V2302All versions < V2302.0004 – All versions < V2302.0004