PT-2022-12433 · Freecad · Freecad

Eldstal

·

Published

2022-01-25

·

Updated

2022-10-27

·

CVE-2021-45845

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FreeCAD version 0.19
Description The Path Sanity Check script is vulnerable to OS command injection, allowing an attacker to execute arbitrary commands via a crafted FCStd document.
Recommendations For FreeCAD version 0.19, consider disabling the Path Sanity Check script until a patch is available to prevent OS command injection attacks.

Exploit

Fix

OS Command Injection

Weakness Enumeration

Related Identifiers

CVE-2021-45845
DSA-5229-1

Affected Products

Freecad