7.8

CVE-2023-24555

A vulnerability has been identified in Solid Edge SE2022 (All versions < V222.0MP12), Solid Edge SE2023 (All versions < V223.0Update2). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted PAR files. This could allow an attacker to execute code in the context of the current process.

Data is provided by the National Vulnerability Database (NVD)
SiemensSolid Edge Se2022 Version-
SiemensSolid Edge Se2022 Versionmaintenance_pack_1
SiemensSolid Edge Se2022 Versionmaintenance_pack_2
SiemensSolid Edge Se2022 Versionmaintenance_pack_3
SiemensSolid Edge Se2022 Versionmaintenance_pack_4
SiemensSolid Edge Se2022 Versionmaintenance_pack_5
SiemensSolid Edge Se2022 Versionmaintenance_pack_7
SiemensSolid Edge Se2022 Versionmaintenance_pack_8
SiemensSolid Edge Se2022 Versionmaintenance_pack_9
SiemensSolid Edge Se2022 Versionmaintenance_pack_10
SiemensSolid Edge Se2022 Versionmaintenance_pack_11
SiemensSolid Edge Se2023 Version < 2210.0002.004
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 0.09% 0.268
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
productcert@siemens.com 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-125 Out-of-bounds Read

The product reads data past the end, or before the beginning, of the intended buffer.