CVE-2022-47967

HIGH

Siemens Solid Edge < V2023 MP1 - Remote Code Execution via Malicious PAR ASM or DFT File Parsing

Title source: llm
STIX 2.1

Description

A vulnerability has been identified in Solid Edge (All versions < V2023 MP1). The DOCMGMT.DLL contains a memory corruption vulnerability that could be triggered while parsing files in different file formats such as PAR, ASM, DFT. This could allow an attacker to execute code in the context of the current process.

References (1)

Core 1
Core References

Scores

CVSS v3 7.8
EPSS 0.0013
EPSS Percentile 31.7%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-119 CWE-787
Status published
Products (2)
siemens/solid_edge se2023
siemens/solid_edge < se2023
Published Jan 10, 2023
Tracked Since Feb 18, 2026