4.3
CVE-2021-41538
- EPSS 0.21%
- Veröffentlicht 28.09.2021 12:15:08
- Zuletzt bearbeitet 21.11.2024 06:26:22
- Quelle productcert@siemens.com
- Teams Watchlist Login
- Unerledigt Login
A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All versions < V1988), Solid Edge SE2021 (All versions < SE2021MP8). The affected application is vulnerable to information disclosure by unexpected access to an uninitialized pointer while parsing user-supplied OBJ files. An attacker could leverage this vulnerability to leak information from unexpected memory locations (ZDI-CAN-13770).
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Siemens ≫ Solid Edge Version < se2021
Siemens ≫ Solid Edge Versionse2021 Update-
Siemens ≫ Solid Edge Versionse2021 Updatemaintenance_pack1
Siemens ≫ Solid Edge Versionse2021 Updatemaintenance_pack2
Siemens ≫ Solid Edge Versionse2021 Updatemaintenance_pack3
Siemens ≫ Solid Edge Versionse2021 Updatemaintenance_pack4
Siemens ≫ Solid Edge Versionse2021 Updatemaintenance_pack5
Siemens ≫ Solid Edge Versionse2021 Updatemaintenance_pack6
Siemens ≫ Solid Edge Versionse2021 Updatemaintenance_pack7
Siemens ≫ Nx 1984 Firmware Version < 1984
Siemens ≫ Nx 1988 Firmware Version < 1984
Siemens ≫ Nx 1957 Firmware Version < 1973.3700
Siemens ≫ Nx 1961 Firmware Version < 1973.3700
Siemens ≫ Nx 1965 Firmware Version < 1973.3700
Siemens ≫ Nx 1969 Firmware Version < 1973.3700
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.21% | 0.404 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 3.3 | 1.8 | 1.4 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
|
nvd@nist.gov | 4.3 | 8.6 | 2.9 |
AV:N/AC:M/Au:N/C:P/I:N/A:N
|
CWE-824 Access of Uninitialized Pointer
The product accesses or uses a pointer that has not been initialized.