{"dataType":"CVE_RECORD","dataVersion":"5.1","cveMetadata":{"cveId":"CVE-2021-38405","assignerOrgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","state":"PUBLISHED","assignerShortName":"icscert","dateReserved":"2021-08-10T19:21:41.085Z","datePublished":"2023-11-21T18:19:10.557Z","dateUpdated":"2024-08-04T01:37:16.588Z"},"containers":{"cna":{"affected":[{"defaultStatus":"unaffected","product":"JT2Go","vendor":"Siemens","versions":[{"lessThan":"13.2.0.7","status":"affected","version":"0","versionType":"custom"}]},{"defaultStatus":"unaffected","product":"Teamcenter Visualization","vendor":"Siemens","versions":[{"lessThan":"12.4.0.13","status":"affected","version":"12.4","versionType":"custom"},{"lessThan":"13.1.0.8","status":"affected","version":"13.1","versionType":"custom"},{"lessThan":"13.2.0.7","status":"affected","version":"13.2","versionType":"custom"},{"lessThan":"13.3.0.1","status":"affected","version":"13.3","versionType":"custom"}]}],"credits":[{"lang":"en","type":"finder","value":"Mat Powell of Trend Micro’s Zero Day Initiative reported these vulnerabilities to Siemens and CISA."}],"datePublic":"2022-06-16T16:46:00.000Z","descriptions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"The Datalogics APDFL library used in affected products is vulnerable to memory corruption condition&nbsp;while parsing specially crafted PDF files. An attacker could leverage this vulnerability to execute code&nbsp;in the context of the current process."}],"value":"The Datalogics APDFL library used in affected products is vulnerable to memory corruption condition while parsing specially crafted PDF files. An attacker could leverage this vulnerability to execute code in the context of the current process."}],"metrics":[{"cvssV3_1":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"NONE","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H","version":"3.1"},"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}]}],"problemTypes":[{"descriptions":[{"cweId":"CWE-119","description":"CWE-119","lang":"en","type":"CWE"}]}],"providerMetadata":{"orgId":"7d14cffa-0d7d-4270-9dc0-52cabd5a23a6","shortName":"icscert","dateUpdated":"2023-11-21T18:19:10.557Z"},"references":[{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-301589.pdf"},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-22-041-07"}],"solutions":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"\n<p>Siemens has released updates for some of the affected products and \nrecommends updating to the latest versions. Siemens is preparing further\n updates and recommends specific countermeasures for products where \nupdates are not yet available.</p>\n<ul><li>JT2Go: <a target=\"_blank\" rel=\"nofollow\" href=\"https://www.plm.automation.siemens.com/global/en/products/plm-components/jt2go.html\">Update to v13.2.0.7</a>&nbsp;or later version</li><li>Teamcenter Visualization v13.1: <a target=\"_blank\" rel=\"nofollow\" href=\"https://support.sw.siemens.com/\">Update to v13.1.0.9 or later version</a></li><li>Teamcenter Visualization v13.2: <a target=\"_blank\" rel=\"nofollow\" href=\"https://support.sw.siemens.com/\">Update to v13.2.0.7 or later version</a></li><li><span style=\"background-color: var(--wht);\">Teamcenter Visualization v13.3: </span><a target=\"_blank\" rel=\"nofollow\" href=\"https://support.sw.siemens.com/\">Update to v13.3.0.1 or later version</a><br></li></ul><p><span style=\"background-color: var(--wht);\">Please see Siemens security advisory </span><a target=\"_blank\" rel=\"nofollow\" href=\"https://cert-portal.siemens.com/productcert/pdf/ssa-301589.pdf\">SSA-301589</a><span style=\"background-color: var(--wht);\">&nbsp;</span><span style=\"background-color: var(--wht);\">for more information.</span><br></p>"}],"value":"Siemens has released updates for some of the affected products and \nrecommends updating to the latest versions. Siemens is preparing further\n updates and recommends specific countermeasures for products where \nupdates are not yet available.\n\n\n  *  JT2Go:  Update to v13.2.0.7 https://www.plm.automation.siemens.com/global/en/products/plm-components/jt2go.html  or later version\n  *  Teamcenter Visualization v13.1:  Update to v13.1.0.9 or later version https://support.sw.siemens.com/ \n  *  Teamcenter Visualization v13.2:  Update to v13.2.0.7 or later version https://support.sw.siemens.com/ \n  *  Teamcenter Visualization v13.3:  Update to v13.3.0.1 or later version https://support.sw.siemens.com/ \n\n\n\nPlease see Siemens security advisory  SSA-301589 https://cert-portal.siemens.com/productcert/pdf/ssa-301589.pdf  for more information."}],"source":{"discovery":"EXTERNAL"},"title":"Siemens Solid Edge, JT2Go, and Teamcenter Visualization Improper Restriction of Operations within the Bounds of a Memory Buffer","workarounds":[{"lang":"en","supportingMedia":[{"base64":false,"type":"text/html","value":"\n\n<p>Siemens has identified the following specific workarounds and mitigations users can apply to reduce the risk:</p>\n<ul><li>Avoid opening untrusted files from unknown sources in affected products.</li>\n</ul><p>As a general security measure, Siemens strongly recommends \nprotecting network access to devices with appropriate mechanisms. In \norder to operate the devices in a protected IT environment, Siemens \nrecommends configuring the environment according to <a target=\"_blank\" rel=\"nofollow\" href=\"https://cert-portal.siemens.com/operational-guidelines-industrial-security.pdf\">Siemens’ operational guidelines for industrial security</a><span style=\"background-color: var(--wht);\">, and to follow the recommendations in the product manuals.</span></p>\n<p>Additional information on industrial security by Siemens can be found on the <a target=\"_blank\" rel=\"nofollow\" href=\"https://www.siemens.com/industrialsecurity\">Siemens industrial security webpage</a><span style=\"background-color: var(--wht);\">.</span></p>\n<p>Please see Siemens security advisory <a target=\"_blank\" rel=\"nofollow\" href=\"https://cert-portal.siemens.com/productcert/pdf/ssa-301589.pdf\">SSA-301589</a>&nbsp;<span style=\"background-color: var(--wht);\">for more information.</span></p>\n\n<br>"}],"value":"Siemens has identified the following specific workarounds and mitigations users can apply to reduce the risk:\n\n\n  *  Avoid opening untrusted files from unknown sources in affected products.\n\n\n\nAs a general security measure, Siemens strongly recommends \nprotecting network access to devices with appropriate mechanisms. In \norder to operate the devices in a protected IT environment, Siemens \nrecommends configuring the environment according to  Siemens’ operational guidelines for industrial security https://cert-portal.siemens.com/operational-guidelines-industrial-security.pdf , and to follow the recommendations in the product manuals.\n\n\nAdditional information on industrial security by Siemens can be found on the  Siemens industrial security webpage https://www.siemens.com/industrialsecurity .\n\n\nPlease see Siemens security advisory  SSA-301589 https://cert-portal.siemens.com/productcert/pdf/ssa-301589.pdf  for more information."}],"x_generator":{"engine":"Vulnogram 0.2.0"}},"adp":[{"providerMetadata":{"orgId":"af854a3a-2127-422b-91ae-364da2661108","shortName":"CVE","dateUpdated":"2024-08-04T01:37:16.588Z"},"title":"CVE Program Container","references":[{"url":"https://cert-portal.siemens.com/productcert/pdf/ssa-301589.pdf","tags":["x_transferred"]},{"url":"https://www.cisa.gov/news-events/ics-advisories/icsa-22-041-07","tags":["x_transferred"]}]}]}}