7.8

CVE-2022-43609

This vulnerability allows remote attackers to execute arbitrary code on affected installations of IronCAD. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of STP files. When parsing the VECTOR element, the process does not properly initialize a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-17672.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
IroncadIroncad Version2022 Update-
IroncadIroncad Version2022 Updatehotfix1
IroncadIroncad Version2022 Updateproduct_update1
IroncadIroncad Version2022 Updateproduct_update1_service_pack1
IroncadIroncad Version2022 Updateproduct_update1_service_pack1_hotfix1
IroncadIroncad Version2022 Updateservice_pack1
IroncadIroncad Version2022 Updateservice_pack1_hotfix1
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.53% 0.809
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
zdi-disclosures@trendmicro.com 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-824 Access of Uninitialized Pointer

The product accesses or uses a pointer that has not been initialized.