PT-2022-4150 · Siemens · Teamcenter

Published

2022-08-09

·

Updated

2022-08-12

·

CVE-2022-34661

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions Teamcenter versions prior to V12.4.0.15 Teamcenter versions prior to V13.0.0.10 Teamcenter versions prior to V13.1.0.10 Teamcenter versions prior to V13.2.0.9 Teamcenter versions prior to V13.3.0.5 Teamcenter versions prior to V14.0.0.2
Description The File Server Cache service in Teamcenter is vulnerable to denial of service by entering infinite loops and using up CPU cycles. This could allow an attacker to cause a denial of service condition. The vulnerability is related to the execution of a cycle with an unavailable exit condition.
Recommendations For Teamcenter versions prior to V12.4.0.15, update to version V12.4.0.15 or later. For Teamcenter versions prior to V13.0.0.10, update to version V13.0.0.10 or later. For Teamcenter versions prior to V13.1.0.10, update to version V13.1.0.10 or later. For Teamcenter versions prior to V13.2.0.9, update to version V13.2.0.9 or later. For Teamcenter versions prior to V13.3.0.5, update to version V13.3.0.5 or later. For Teamcenter versions prior to V14.0.0.2, update to version V14.0.0.2 or later. As a temporary workaround, consider disabling the File Server Cache service to minimize the risk of exploitation.

Fix

Infinite Loop

Weakness Enumeration

Related Identifiers

BDU:2022-04993
CVE-2022-34661

Affected Products

Teamcenter