PT-2021-4190 · Siemens · Simcenter Star-Ccm+ Viewer

Francis Provencher

·

Published

2021-06-04

·

Updated

2021-09-23

·

CVE-2021-25665

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Simcenter STAR-CCM+ Viewer versions prior to V2021.2.1
Description The issue is related to a buffer overflow when parsing SCE format files, which could allow an attacker to execute arbitrary code or cause a denial of service by using a specially crafted file. The starview+.exe application lacks proper validation of user-supplied data when parsing scene files, resulting in an out of bounds write past the end of an allocated structure.
Recommendations For versions prior to V2021.2.1, update to version V2021.2.1 or later to resolve the issue. As a temporary workaround, consider restricting the use of the starview+.exe application until a patch is applied. Avoid using the application to parse untrusted or unknown SCE format files until the issue is resolved.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-04786
CVE-2021-25665
ZDI-21-1074

Affected Products

Simcenter Star-Ccm+ Viewer