#VU65324 Buffer overflow in PADS Standard/Plus Viewer - CVE-2022-34290

 

#VU65324 Buffer overflow in PADS Standard/Plus Viewer - CVE-2022-34290

Published: July 14, 2022 / Updated: July 14, 2022


Vulnerability identifier: #VU65324
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-34290
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
PADS Standard/Plus Viewer
Software vendor:
Siemens

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary error while parsing PCB files. A remote attacker can create a specially crafted PCB file, trick the victim into opening it, trigger memory corruption and read contents of memory on the system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links