PT-2021-23326 · Siemens · Teamcenter Active Workspace
Published
2021-12-14
·
Updated
2021-12-16
·
CVE-2021-41547
CVSS v3.1
7.2
High
| Vector | AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Teamcenter Active Workspace versions prior to 4.3.11
Teamcenter Active Workspace versions prior to 5.0.10
Teamcenter Active Workspace versions prior to 5.1.6
Teamcenter Active Workspace versions prior to 5.2.3
Description
The application contains an unsafe unzipping pattern that could lead to a zip path traversal attack. This could allow an attacker to execute a remote shell with admin rights.
Recommendations
For versions prior to 4.3.11, update to version 4.3.11 or later.
For versions prior to 5.0.10, update to version 5.0.10 or later.
For versions prior to 5.1.6, update to version 5.1.6 or later.
For versions prior to 5.2.3, update to version 5.2.3 or later.
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teamcenter Active Workspace