PT-2022-3369 · Siemens · Teamcenter

Published

2022-05-10

·

Updated

2023-02-23

·

CVE-2022-24290

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Teamcenter versions prior to V12.4.0.13 Teamcenter versions prior to V13.0.0.9 Teamcenter versions prior to V13.2.0.8 Teamcenter versions prior to V13.3.0.3 Teamcenter versions prior to V14.0.0.2 Teamcenter V13.1 (all versions)
Description A stack overflow condition exists in the tcserver.exe binary of affected Teamcenter applications during the parsing of user input, potentially leading to a crash. The vulnerability can be exploited by a remote attacker to cause a denial of service.
Recommendations For Teamcenter versions prior to V12.4.0.13, update to version V12.4.0.13 or later. For Teamcenter versions prior to V13.0.0.9, update to version V13.0.0.9 or later. For Teamcenter versions prior to V13.2.0.8, update to version V13.2.0.8 or later. For Teamcenter versions prior to V13.3.0.3, update to version V13.3.0.3 or later. For Teamcenter versions prior to V14.0.0.2, update to version V14.0.0.2 or later. For Teamcenter V13.1, consider disabling the tcserver.exe binary until a patch is available.

Fix

Memory Corruption

Stack Overflow

Weakness Enumeration

Related Identifiers

BDU:2022-04136
CVE-2022-24290

Affected Products

Teamcenter