7.8

CVE-2021-41535

A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All versions < V1988), Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13771).

Data is provided by the National Vulnerability Database (NVD)
SiemensSolid Edge Version < se2021
SiemensSolid Edge Versionse2021 Update-
SiemensSolid Edge Versionse2021 Updatemaintenance_pack1
SiemensSolid Edge Versionse2021 Updatemaintenance_pack2
SiemensSolid Edge Versionse2021 Updatemaintenance_pack3
SiemensSolid Edge Versionse2021 Updatemaintenance_pack4
SiemensSolid Edge Versionse2021 Updatemaintenance_pack5
SiemensSolid Edge Versionse2021 Updatemaintenance_pack6
SiemensSolid Edge Versionse2021 Updatemaintenance_pack7
SiemensNx 1984 Firmware Version < 1984
   SiemensNx 1984 Version-
SiemensNx 1988 Firmware Version < 1984
   SiemensNx 1988 Version-
SiemensNx 1957 Firmware Version < 1973.3700
   SiemensNx 1957 Version-
SiemensNx 1961 Firmware Version < 1973.3700
   SiemensNx 1961 Version-
SiemensNx 1965 Firmware Version < 1973.3700
   SiemensNx 1965 Version-
SiemensNx 1969 Firmware Version < 1973.3700
   SiemensNx 1969 Version-
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.59% 0.666
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 6.8 8.6 6.4
AV:N/AC:M/Au:N/C:P/I:P/A:P
CWE-416 Use After Free

The product reuses or references memory after it has been freed. At some point afterward, the memory may be allocated again and saved in another pointer, while the original pointer references a location somewhere within the new allocation. Any operations using the original pointer are no longer valid because the memory "belongs" to the code that operates on the new pointer.