CVE-2022-27873

An attacker can force the victims device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360s document parser. The vulnerability exists in the applications Insert SVG procedure. An attacker can also leverage this vulnerability to obtain victims public IP and possibly other sensitive information.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
NONE
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
autodeskCNA
---
---
CVEADP
---
---