Known vulnerabilities in Autodesk Infraworks 2020.2 Hotfix 4 - page 3

Vendor: Autodesk
Version: 2020.2 Hotfix 4
Software CPE: cpe:2.3:a:autodesk:autodesk_infraworks:*:*:*:*:*:*:*:*
Total vulnerabilities: 61
Public exploits: 8
Known exploited (KEV): 2
Highest CVSSv4 Score: 9.3

Vulnerabilities by Severity

Severity distribution of vulnerabilities affecting Autodesk Infraworks version 2020.2 Hotfix 4 Autodesk Infraworks 2020.2 Hotfix 4 is affected by 61 vulnerabilities: 1 critical, 14 high, 29 medium, 17 low Critical High Medium Low

Vulnerabilities (61)

Vulnerability CWE-ID CSH Severity Public Exploit KEV First fixed release Published Bulletins
#VU73175 - Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CVE-2022-31159
CWE-22 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 08.03.2023 SB2023030823
SB2023030915
SB2023042635
and 15 more
#VU63127 - Resource exhaustion
CVE-2021-37136
CWE-400 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 12.05.2022 SB2021101948
SB2022051235
SB2022060838
and 36 more
#VU61953 - Memory corruption
CVE-2022-25795
CWE-119 Medium
No
No
2020.2 Hotfix 6, 2021.2 Hotfix 6, 2022.1 Hotfix 4 07.04.2022 SB2022040706
SB2022042625
#VU61952 - Memory corruption
CVE-2022-25797
CWE-119 High
No
No
2020.2 Hotfix 6, 2021.2 Hotfix 6, 2022.1 Hotfix 4 07.04.2022 SB2022040706
SB2022042625
#VU61951 - Out-of-bounds read
CVE-2022-27524
CWE-125 Medium
No
No
2020.2 Hotfix 6, 2021.2 Hotfix 6, 2022.1 Hotfix 4 07.04.2022 SB2022040706
SB2022042625
#VU61950 - Out-of-bounds read
CVE-2022-27523
CWE-125 Medium
No
No
2020.2 Hotfix 6, 2021.2 Hotfix 6, 2022.1 Hotfix 4 07.04.2022 SB2022040706
SB2022042625
#VU61810 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-43797
CWE-444 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 02.04.2022 SB2021120923
SB2022040202
SB2022042223
and 49 more
#VU61799 - Out-of-bounds write
CVE-2020-36518
CWE-787 Medium
No
No
2020.2 Hotfix 7, 2021.2 Hotfix 7, 2022.1.5 Hotfix 5, 2023.0.1 Hotfix 1 01.04.2022 SB2022040113
SB2022040114
SB2022040115
and 147 more
#VU59924 - Improper input validation
CVE-2021-37137
CWE-20 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 23.01.2022 SB2022012310
SB2022012745
SB2022012753
and 43 more
#VU58751 - Out-of-bounds read
CVE-2021-40160
CWE-125 Low
No
No
2020.2 Hotfix 6, 2021.2 Hotfix 6, 2022.1 Hotfix 4 09.12.2021 SB2021120904
SB2021120916
SB2022042625
#VU56063 - Memory corruption
CVE-2021-3711
CWE-119 High
No
No
2020.2 Hotfix 7, 2021.2 Hotfix 7, 2022.1.5 Hotfix 5, 2023.0.1 Hotfix 1 24.08.2021 SB2021082414
SB2021082508
SB2021082510
and 53 more
#VU54379 - Out-of-bounds write
CVE-2021-27043
CWE-787 High
No
No
2020.2 Hotfix 6, 2021.2 Hotfix 6, 2022.1 Hotfix 4 24.06.2021 SB2021062412
SB2021062413
SB2021062414
and 9 more
#VU54378 - Memory corruption
CVE-2021-27042
CWE-119 High
No
No
2020.2 Hotfix 6, 2021.2 Hotfix 6, 2022.1 Hotfix 4 24.06.2021 SB2021062412
SB2021062413
SB2021062414
and 9 more
#VU54377 - Memory corruption
CVE-2021-27041
CWE-119 High
No
No
2020.2 Hotfix 6, 2021.2 Hotfix 6, 2022.1 Hotfix 4 24.06.2021 SB2021062412
SB2021062413
SB2021062414
and 11 more
#VU54376 - Out-of-bounds read
CVE-2021-27040
CWE-125 High
No
No
2020.2 Hotfix 6, 2021.2 Hotfix 6, 2022.1 Hotfix 4 24.06.2021 SB2021062412
SB2021062413
SB2021062414
and 10 more
#VU51836 - Inconsistent Interpretation of HTTP Requests ('HTTP Request Smuggling')
CVE-2021-21295
CWE-444 Medium
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 01.04.2021 SB2021040115
SB2021040626
SB2021050706
and 26 more
#VU49739 - Improper input validation
CVE-2020-5421
CWE-20 Medium
Public exploit available
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 20.01.2021 SB2021012002
SB2021012008
SB2021012015
and 39 more
#VU48175 - Improper input validation
CVE-2020-27955
CWE-20 High
Public exploit available
No
2020.2 Hotfix 6, 2021.2 Hotfix 6, 2022.1 Hotfix 4 05.11.2020 SB2020110606
SB2022042625
#VU15467 - Improper input validation
CVE-2018-15756
CWE-20 Low
No
No
2021.2 Hotfix 9, 2023.1 Hotfix 1 22.10.2018 SB2018102305
SB2020012203
SB2020032701
and 28 more
#VU11918 - Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting')
CVE-2018-1273
CWE-113 High
Public exploit available
Exploited
2021.2 Hotfix 9, 2023.1 Hotfix 1 18.04.2018 SB2018041815
SB2022072013
SB2023011758
and 2 more


Showing elements 41 - 60 out of 61