CVE-2021-43336

HIGH

Open Design Alliance Drawings SDK <2022.11 - Memory Corruption

Title source: llm
STIX 2.1

Description

An Out-of-Bounds Write vulnerability exists when reading a DXF or DWG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF and DWG files. Crafted data in a DXF or DWG file (an invalid number of properties) can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.

Scores

CVSS v3 7.8
EPSS 0.0035
EPSS Percentile 57.3%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CWE
CWE-787
Status published
Products (5)
opendesign/drawings_software_development_kit < 2022.11
siemens/jt2go
siemens/solid_edge se2022
siemens/teamcenter_visualization 13.1.0
siemens/teamcenter_visualization 12.4.0 - 12.4.0.13
Published Nov 14, 2021
Tracked Since Feb 18, 2026