← back
CVE-2021-38405

Siemens Solid Edge, JT2Go, and Teamcenter Visualization Improper Restriction of Operations within the Bounds of a Memory Buffer

CVSS 7.8 HIGHEPSS 1.3%CWE-119
Vexday Risk Score
21Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 7.8EPSS 1.3%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
21 Nov 2023Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
The Datalogics APDFL library used in affected products is vulnerable to memory corruption condition while parsing specially crafted PDF files. An attacker could leverage this vulnerability to execute code in the context of the current process.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →