Brief

Here is a summary of the document in a concise format:

Vulnerability Summary:

Product: PS/IGES Parasolid Translator Component
Vendor: Siemens
Version: Prior to V27.1.215
Vulnerability Type: Out-of-bounds read, Type confusion, Improper restriction of operations within the bounds of a memory buffer
CVSS v3 Score: 7.8 (High)
CVSS v4 Score: 7.3 (High)
Description: The affected application contains vulnerabilities that could allow an attacker to execute code in the context of the current process.

Mitigation: Update to V27.1.215 or later version. Implement defensive measures to minimize the risk of exploitation, such as not opening untrusted IGS files and configuring the environment according to Siemens' operational guidelines for industrial security.

Additional Information:

A CVSS v3 and v4 score has been calculated for each vulnerability.
The vulnerabilities are not exploitable remotely and no known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.
The recommended mitigation steps and additional security measures are available on the Siemens security advisory webpage and CISA's ICS webpage.

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens’ ProductCERT Security Advisories (CERT Services | Services | Siemens Global).  View CSAF 1. EXECUTIVE SUMMARY CVSS v3 7.8 ATTENTION: Low Attack Complexity

This content is restricted.

Highlights content goes here...

As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens’ ProductCERT Security Advisories (CERT Services | Services | Siemens Global).  View CSAF 1. EXECUTIVE SUMMARY CVSS v3 7.8 ATTENTION: Low Attack Complexity

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies