PT-2022-3369 · Siemens · Teamcenter
Published
2022-05-10
·
Updated
2023-02-23
·
CVE-2022-24290
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Teamcenter versions prior to V12.4.0.13
Teamcenter versions prior to V13.0.0.9
Teamcenter versions prior to V13.2.0.8
Teamcenter versions prior to V13.3.0.3
Teamcenter versions prior to V14.0.0.2
Teamcenter V13.1 (all versions)
Description
A stack overflow condition exists in the tcserver.exe binary of affected Teamcenter applications during the parsing of user input, potentially leading to a crash. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations
For Teamcenter versions prior to V12.4.0.13, update to version V12.4.0.13 or later.
For Teamcenter versions prior to V13.0.0.9, update to version V13.0.0.9 or later.
For Teamcenter versions prior to V13.2.0.8, update to version V13.2.0.8 or later.
For Teamcenter versions prior to V13.3.0.3, update to version V13.3.0.3 or later.
For Teamcenter versions prior to V14.0.0.2, update to version V14.0.0.2 or later.
For Teamcenter V13.1, consider disabling the tcserver.exe binary until a patch is available.
Fix
Memory Corruption
Stack Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Teamcenter