Use-after-free in Siemens products - CVE-2023-28830
Published: August 10, 2023
Vulnerability identifier: #VU79323
CSH Severity: High
CVSS v4: 8.6 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2023-28830
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to compromise vulnerable system.
The vulnerability exists due to a use-after-free error while parsing specially crafted ASM file. A remote attacker can trick a victim to open a specially crafted file and execute arbitrary code on the target system.
Affected software
Teamcenter Visualization
JT2Go
Solid Edge SE2022
Solid Edge SE2023
JT2Go
Solid Edge SE2022
Solid Edge SE2023
How to mitigate CVE-2023-28830
Install updates from vendor's website.
Teamcenter Visualization - addressed in versions 13.2.0.15, 13.3.0.11, 14.1.0.11, 14.2.0.5
JT2Go - update to 14.2.0.5
Solid Edge SE2022 - update to 222.0 Update 13
Solid Edge SE2023 - update to 223.0 Update 4
JT2Go - update to 14.2.0.5
Solid Edge SE2022 - update to 222.0 Update 13
Solid Edge SE2023 - update to 223.0 Update 4