CVE-2021-32946

An improper check for unusual or exceptional conditions issue exists within the parsing DGN files from Drawings SDK (Version 2022.4 and prior) resulting from the lack of proper validation of the user-supplied data. This may result in several of out-of-bounds problems and allow attackers to cause a denial-of-service condition or execute code in the context of the current process.
Configurations

Configuration 1 (hide)

cpe:2.3:a:opendesign:drawings_sdk:*:*:*:*:*:*:*:*

Configuration 2 (hide)

OR cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*

History

15 Apr 2022, 15:39

Type Values Removed Values Added
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-155599.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-155599.pdf - Patch, Third Party Advisory
References (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-985/ - (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-985/ - Third Party Advisory, VDB Entry
First Time Siemens comos
CPE cpe:2.3:a:siemens:comos:*:*:*:*:*:*:*:*

10 Mar 2022, 17:42

Type Values Removed Values Added
References
  • (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-155599.pdf -
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-985/ -

21 Sep 2021, 16:39

Type Values Removed Values Added
CPE cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
References
  • (MISC) https://www.zerodayinitiative.com/advisories/ZDI-21-983/ - Third Party Advisory, VDB Entry
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-938030.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-938030.pdf - Third Party Advisory

18 Aug 2021, 17:15

Type Values Removed Values Added
References
  • (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-938030.pdf -

21 Jun 2021, 21:47

Type Values Removed Values Added
CWE CWE-754
CVSS v2 : unknown
v3 : unknown
v2 : 6.8
v3 : 7.8
References (MISC) https://us-cert.cisa.gov/ics/advisories/icsa-21-159-02 - (MISC) https://us-cert.cisa.gov/ics/advisories/icsa-21-159-02 - Third Party Advisory, US Government Resource
CPE cpe:2.3:a:opendesign:drawings_sdk:*:*:*:*:*:*:*:*

17 Jun 2021, 12:15

Type Values Removed Values Added
New CVE

Information

Published : 2021-06-17 12:15

Updated : 2023-12-10 13:55


NVD link : CVE-2021-32946

Mitre link : CVE-2021-32946

CVE.ORG link : CVE-2021-32946


JSON object : View

Products Affected

siemens

  • jt2go
  • comos
  • teamcenter_visualization

opendesign

  • drawings_sdk
CWE
CWE-754

Improper Check for Unusual or Exceptional Conditions