ID

VAR-202207-0944


CVE

CVE-2022-2069


TITLE

Siemens Teamcenter Visualization Buffer error vulnerability

Trust: 0.6

sources: CNNVD: CNNVD-202207-1226

DESCRIPTION

The APDFL.dll in Siemens JT2Go prior to V13.3.0.5 and Siemens Teamcenter Visualization prior to V14.0.0.2 contains an out of bounds write past the fixed-length heap-based buffer while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process. Siemens Datalogics File Parsing Vulnerability

Trust: 0.99

sources: NVD: CVE-2022-2069 // VULMON: CVE-2022-2069

AFFECTED PRODUCTS

vendor:siemensmodel:teamcenter visualizationscope:ltversion:14.0.0.2

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:14.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:13.3.0

Trust: 1.0

vendor:siemensmodel:jt2goscope:ltversion:13.3.0.5

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:13.3.0.5

Trust: 1.0

sources: NVD: CVE-2022-2069

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2022-2069
value: HIGH

Trust: 1.0

ics-cert@hq.dhs.gov: CVE-2022-2069
value: HIGH

Trust: 1.0

CNNVD: CNNVD-202207-1226
value: HIGH

Trust: 0.6

NVD:
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 2.0

sources: NVD: CVE-2022-2069 // NVD: CVE-2022-2069 // CNNVD: CNNVD-202207-1226

PROBLEMTYPE DATA

problemtype:CWE-787

Trust: 1.0

sources: NVD: CVE-2022-2069

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202207-1226

TYPE

buffer error

Trust: 0.6

sources: CNNVD: CNNVD-202207-1226

CONFIGURATIONS

sources: NVD: CVE-2022-2069

PATCH

title:Siemens Teamcenter Visualization Buffer error vulnerability fixurl:http://123.124.177.30/web/xxk/bdxqbyid.tag?id=211645

Trust: 0.6

sources: CNNVD: CNNVD-202207-1226

EXTERNAL IDS

db:ICS CERTid:ICSA-22-195-07

Trust: 1.7

db:NVDid:CVE-2022-2069

Trust: 1.7

db:SIEMENSid:SSA-829738

Trust: 1.6

db:CS-HELPid:SB2022071337

Trust: 0.6

db:CNNVDid:CNNVD-202207-1226

Trust: 0.6

db:VULMONid:CVE-2022-2069

Trust: 0.1

sources: VULMON: CVE-2022-2069 // NVD: CVE-2022-2069 // CNNVD: CNNVD-202207-1226

REFERENCES

url:https://www.cisa.gov/uscert/ics/advisories/icsa-22-195-07

Trust: 1.7

url:https://cert-portal.siemens.com/productcert/pdf/ssa-829738.pdf

Trust: 1.6

url:https://cxsecurity.com/cveshow/cve-2022-2069/

Trust: 0.6

url:https://us-cert.cisa.gov/ics/advisories/icsa-22-195-07

Trust: 0.6

url:https://www.cybersecurity-help.cz/vdb/sb2022071337

Trust: 0.6

sources: VULMON: CVE-2022-2069 // NVD: CVE-2022-2069 // CNNVD: CNNVD-202207-1226

CREDITS

Siemens reported this vulnerability to CISA.

Trust: 0.6

sources: CNNVD: CNNVD-202207-1226

SOURCES

db:VULMONid:CVE-2022-2069
db:NVDid:CVE-2022-2069
db:CNNVDid:CNNVD-202207-1226

LAST UPDATE DATE

2023-12-18T14:03:51.833000+00:00


SOURCES UPDATE DATE

db:NVDid:CVE-2022-2069date:2022-10-21T19:05:52.447
db:CNNVDid:CNNVD-202207-1226date:2022-10-24T00:00:00

SOURCES RELEASE DATE

db:NVDid:CVE-2022-2069date:2022-10-20T17:15:09.937
db:CNNVDid:CNNVD-202207-1226date:2022-07-13T00:00:00