PT-2022-4150 · Siemens · Teamcenter
Published
2022-08-09
·
Updated
2022-08-12
·
CVE-2022-34661
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
Teamcenter versions prior to V12.4.0.15
Teamcenter versions prior to V13.0.0.10
Teamcenter versions prior to V13.1.0.10
Teamcenter versions prior to V13.2.0.9
Teamcenter versions prior to V13.3.0.5
Teamcenter versions prior to V14.0.0.2
Description
The File Server Cache service in Teamcenter is vulnerable to denial of service by entering infinite loops and using up CPU cycles. This could allow an attacker to cause a denial of service condition. The vulnerability is related to the execution of a cycle with an unavailable exit condition.
Recommendations
For Teamcenter versions prior to V12.4.0.15, update to version V12.4.0.15 or later.
For Teamcenter versions prior to V13.0.0.10, update to version V13.0.0.10 or later.
For Teamcenter versions prior to V13.1.0.10, update to version V13.1.0.10 or later.
For Teamcenter versions prior to V13.2.0.9, update to version V13.2.0.9 or later.
For Teamcenter versions prior to V13.3.0.5, update to version V13.3.0.5 or later.
For Teamcenter versions prior to V14.0.0.2, update to version V14.0.0.2 or later.
As a temporary workaround, consider disabling the File Server Cache service to minimize the risk of exploitation.
Fix
Infinite Loop
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Teamcenter