PT-2022-4921 · Siemens · Simcenter Femap

Published

2022-04-12

·

Updated

2022-04-19

·

CVE-2022-28662

CVSS v2.0

7.1

High

VectorAV:N/AC:M/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Simcenter Femap versions prior to V2022.1.2
Description The issue is caused by a buffer overflow in dynamic memory, which can be exploited by analyzing specially crafted .NEU files. This could allow a remote attacker to leak protected information in the context of the current process.
Recommendations For Simcenter Femap versions prior to V2022.1.2, update to version V2022.1.2 or later to resolve the issue. As a temporary workaround, consider avoiding the use of specially crafted .NEU files until the update is applied. Restrict access to the application to minimize the risk of exploitation.

Fix

Memory Corruption

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-06093
CVE-2022-28662

Affected Products

Simcenter Femap