CVE-2021-46158
09.02.2022, 16:15
A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). Affected application contains a stack based buffer overflow vulnerability while parsing NEU files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-15085, ZDI-CAN-15289, ZDI-CAN-15602)Enginsight
Vendor | Product | Version |
---|---|---|
siemens | simcenter_femap | 2020.2 |
siemens | simcenter_femap | 2020.2:maintenance_pack1 |
siemens | simcenter_femap | 2020.2:maintenance_pack2 |
siemens | simcenter_femap | 2020.2:maintenance_pack3 |
siemens | simcenter_femap | 2021.1 |
siemens | simcenter_femap | 2021.1:maintenance_pack1 |
siemens | simcenter_femap | 2021.1:maintenance_pack2 |
siemens | simcenter_femap | 2021.1:maintenance_pack3 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-121 - Stack-based Buffer OverflowA stack-based buffer overflow condition is a condition where the buffer being overwritten is allocated on the stack (i.e., is a local variable or, rarely, a parameter to a function).
- CWE-1284 - Improper Validation of Specified Quantity in InputThe product receives input that is expected to specify a quantity (such as size or length), but it does not validate or incorrectly validates that the quantity has the required properties.
References