CVE-2022-27873
29.07.2022, 16:15
An attacker can force the victims device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360s document parser. The vulnerability exists in the applications Insert SVG procedure. An attacker can also leverage this vulnerability to obtain victims public IP and possibly other sensitive information.Enginsight
Vendor | Product | Version |
---|---|---|
autodesk | fusion_360 | 𝑥 ≤ 2.0.12887 |
𝑥
= Vulnerable software versions