Type conversion in Open Design Alliance products - CVE-2021-25175
Published: February 11, 2021 / Updated: February 25, 2021
Vulnerability identifier: #VU50637
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-25175
CWE-ID: CWE-704
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to execute arbitrary code on the system.
The vulnerability exists due to a memory corruption when rendering malformed DXF and DWG files. A remote attacker can trigger memory corruption and execute arbitrary code on the target system.
Affected software
JT2Go
Teamcenter Visualization
Drawings SDK
Siemens COMOS
Teamcenter Visualization
Drawings SDK
Siemens COMOS
How to mitigate CVE-2021-25175
Install updates from vendor's website.
JT2Go - update to 13.1.0.1
Teamcenter Visualization - update to 13.1.0.1
Drawings SDK - update to 2021.11
Siemens COMOS - update to 10.4.1
Teamcenter Visualization - update to 13.1.0.1
Drawings SDK - update to 2021.11
Siemens COMOS - update to 10.4.1