Buffer overflow in PADS Standard/Plus Viewer - CVE-2022-34287

 

Buffer overflow in PADS Standard/Plus Viewer - CVE-2022-34287

Published: July 14, 2022 / Updated: July 14, 2022


Vulnerability identifier: #VU65321
CSH Severity: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-34287
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
PADS Standard/Plus Viewer
Software vendor:
Siemens

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary error while parsing PCB files. A remote attacker can create a specially crafted PCB files, trick the victim into opening it, trigger memory corruption and read contents of memory on the system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links