#VU65325 Buffer overflow in PADS Standard/Plus Viewer - CVE-2022-34291

 

#VU65325 Buffer overflow in PADS Standard/Plus Viewer - CVE-2022-34291

Published: July 14, 2022 / Updated: July 14, 2022


Vulnerability identifier: #VU65325
Vulnerability risk: Medium
CVSSv4.0: CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:U/U:Green
CVE-ID: CVE-2022-34291
CWE-ID: CWE-119
Exploitation vector: Remote access
Exploit availability: No public exploit available
Vulnerable software:
PADS Standard/Plus Viewer
Software vendor:
Siemens

Description

The vulnerability allows a remote attacker to gain access to potentially sensitive information.

The vulnerability exists due to a boundary error while parsing PCB files. A remote attacker can create a specially crafted PCB file, trick the victim into opening it, trigger memory corruption and read contents of memory on the system.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links