PT-2021-23326 · Siemens · Teamcenter Active Workspace

Published

2021-12-14

·

Updated

2021-12-16

·

CVE-2021-41547

CVSS v3.1

7.2

High

VectorAV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Teamcenter Active Workspace versions prior to 4.3.11 Teamcenter Active Workspace versions prior to 5.0.10 Teamcenter Active Workspace versions prior to 5.1.6 Teamcenter Active Workspace versions prior to 5.2.3
Description The application contains an unsafe unzipping pattern that could lead to a zip path traversal attack. This could allow an attacker to execute a remote shell with admin rights.
Recommendations For versions prior to 4.3.11, update to version 4.3.11 or later. For versions prior to 5.0.10, update to version 5.0.10 or later. For versions prior to 5.1.6, update to version 5.1.6 or later. For versions prior to 5.2.3, update to version 5.2.3 or later.

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2021-41547

Affected Products

Teamcenter Active Workspace