CVE-2022-41851

HIGH

JTTK < V11.1.1.0, Simcenter Femap V2022.1 < V2022.1.3, Simcenter Fe...

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in JTTK (All versions < V11.1.1.0), Simcenter Femap V2022.1 (All versions < V2022.1.3), Simcenter Femap V2022.2 (All versions < V2022.2.2). The JTTK library is vulnerable to an uninitialized pointer reference vulnerability while parsing specially crafted JT files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-16973)

Scores

CVSS v3 7.8
EPSS 0.0006
EPSS Percentile 19.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-824
Status published
Products (2)
siemens/jt_open_toolkit < 11.1.1.0
siemens/simcenter_femap 2022.1.0 - 2022.1.3
Published Oct 11, 2022
Tracked Since Feb 18, 2026