PT-2022-18658 · Autodesk · Autodesk Fusion 360

Published

2022-07-29

·

Updated

2022-08-05

·

CVE-2022-27873

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Autodesk Fusion 360 (affected versions not specified)
Description The issue allows an attacker to force a victim's device to perform arbitrary HTTP requests in WAN through a malicious SVG file being parsed by Autodesk Fusion 360's document parser. This occurs in the application's 'Insert SVG' procedure. An attacker can also leverage this to obtain the victim's public IP and possibly other sensitive information.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Weakness Enumeration

Related Identifiers

CVE-2022-27873

Affected Products

Autodesk Fusion 360