PT-2022-4151 · Siemens · Teamcenter

Published

2022-08-09

·

Updated

2022-08-12

·

CVE-2022-34660

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Teamcenter versions prior to V12.4.0.15 Teamcenter versions prior to V13.0.0.10 Teamcenter versions prior to V13.1.0.10 Teamcenter versions prior to V13.2.0.9 Teamcenter versions prior to V13.3.0.5 Teamcenter versions prior to V14.0.0.2
Description The issue is related to insufficient argument validation in the File Server Cache service of Teamcenter, which could allow a remote attacker to execute arbitrary commands. This vulnerability may potentially enable an attacker to perform remote code execution.
Recommendations For Teamcenter versions prior to V12.4.0.15, update to version V12.4.0.15 or later. For Teamcenter versions prior to V13.0.0.10, update to version V13.0.0.10 or later. For Teamcenter versions prior to V13.1.0.10, update to version V13.1.0.10 or later. For Teamcenter versions prior to V13.2.0.9, update to version V13.2.0.9 or later. For Teamcenter versions prior to V13.3.0.5, update to version V13.3.0.5 or later. For Teamcenter versions prior to V14.0.0.2, update to version V14.0.0.2 or later.

Fix

Command Injection

Weakness Enumeration

Related Identifiers

BDU:2022-04994
CVE-2022-34660

Affected Products

Teamcenter