CVE-2022-29028

A vulnerability has been identified in JT2Go (All versions < V13.3.0.3), Teamcenter Visualization V13.3 (All versions < V13.3.0.3), Teamcenter Visualization V14.0 (All versions < V14.0.0.1). The Tiff_Loader.dll is vulnerable to infinite loop condition while parsing specially crafted TIFF files. An attacker could leverage this vulnerability to crash the application causing denial of service condition.
References
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*

History

26 May 2022, 16:19

Type Values Removed Values Added
First Time Siemens
Siemens jt2go
Siemens teamcenter Visualization
References (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-553086.pdf - (CONFIRM) https://cert-portal.siemens.com/productcert/pdf/ssa-553086.pdf - Patch, Vendor Advisory
CVSS v2 : unknown
v3 : unknown
v2 : 4.3
v3 : 5.5
CWE CWE-835
CPE cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*
cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*

20 May 2022, 13:43

Type Values Removed Values Added
New CVE

Information

Published : 2022-05-20 13:15

Updated : 2023-12-10 14:22


NVD link : CVE-2022-29028

Mitre link : CVE-2022-29028

CVE.ORG link : CVE-2022-29028


JSON object : View

Products Affected

siemens

  • jt2go
  • teamcenter_visualization
CWE
CWE-835

Loop with Unreachable Exit Condition ('Infinite Loop')