CVE-2023-33123
CVSS 3.1 Score 7.8 of 10 (high)
Details
Published Jun 13, 2023
Updated: Jun 21, 2023
CWE ID 125
Summary
CVE-2023-33123 is a newly identified vulnerability that affects multiple versions of JT2Go and Teamcenter Visualization applications. These versions include V13.2, V13.3, V14.0, V14.1, and V14.2, all below certain specified updates. The issue lies in the way these applications parse CGM (Computer-aided Design Graphics Exchange) files. An out-of-bounds read occurs, enabling an attacker to access memory beyond the allocated structure. By exploiting this vulnerability, an attacker could potentially execute arbitrary code within the current process.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Products
- Siemens Teamcenter Visualization
- Siemens JT2GO
- Teamcenter
Affected Vendors
- Siemens AG