CVE-2022-34659

HIGH

Simcenter STAR-CCM+ Viewer - Unauthorized Exposure of User and Host Information via Power-on-Demand License Server

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in Simcenter STAR-CCM+ (All versions only if the Power-on-Demand public license server is used). Affected applications expose user, host and display name of users, when the public license server is used. This could allow an attacker to retrieve this information.

References (1)

Core 1
Core References
Mitigation, Vendor Advisory x_refsource_misc
https://cert-portal.siemens.com/productcert/pdf/ssa-555707.pdf

Scores

CVSS v3 7.5
EPSS 0.0034
EPSS Percentile 56.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (1)
siemens/simcenter_star-ccm\+_viewer
Published Aug 10, 2022
Tracked Since Feb 18, 2026