ID

VAR-202304-1229


CVE

CVE-2023-1709


TITLE

Siemens Teamcenter Visualization Security hole

Trust: 0.6

sources: CNNVD: CNNVD-202304-1222

DESCRIPTION

Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an attack that causes an unhandled crash during the rendering process. The APDFL.dll contains a memory corruption vulnerability while parsing specially crafted PDF files. This could allow an malicious user to execute code in the context of the current process

Trust: 0.99

sources: NVD: CVE-2023-1709 // VULMON: CVE-2023-1709

AFFECTED PRODUCTS

vendor:siemensmodel:jt2goscope:ltversion:14.2.0.2

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:13.2.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:14.1

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:14.1.0.7

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:14.0.0.5

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:14.2.0.2

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:14.2

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:13.2.0.13

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:14.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:gteversion:13.3.0

Trust: 1.0

vendor:siemensmodel:teamcenter visualizationscope:ltversion:13.3.0.9

Trust: 1.0

sources: NVD: CVE-2023-1709

CVSS

SEVERITY

CVSSV2

CVSSV3

NVD: CVE-2023-1709
value: HIGH

Trust: 1.0

ics-cert@hq.dhs.gov: CVE-2023-1709
value: HIGH

Trust: 1.0

CNNVD: CNNVD-202304-1222
value: HIGH

Trust: 0.6

NVD:
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: REQUIRED
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.1

Trust: 2.0

sources: NVD: CVE-2023-1709 // NVD: CVE-2023-1709 // CNNVD: CNNVD-202304-1222

PROBLEMTYPE DATA

problemtype:CWE-121

Trust: 1.0

sources: NVD: CVE-2023-1709

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-202304-1222

TYPE

other

Trust: 0.6

sources: CNNVD: CNNVD-202304-1222

CONFIGURATIONS

sources: NVD: CVE-2023-1709

PATCH

title:Siemens Teamcenter Visualization Security vulnerabilitiesurl:http://123.124.177.30/web/xxk/bdxqbyid.tag?id=240818

Trust: 0.6

sources: CNNVD: CNNVD-202304-1222

EXTERNAL IDS

db:ICS CERTid:ICSA-23-103-11

Trust: 1.7

db:SIEMENSid:SSA-629917

Trust: 1.7

db:NVDid:CVE-2023-1709

Trust: 1.7

db:ICS CERTid:ICSA-23-164-01

Trust: 1.6

db:AUSCERTid:ESB-2023.2160

Trust: 0.6

db:CNNVDid:CNNVD-202304-1222

Trust: 0.6

db:VULMONid:CVE-2023-1709

Trust: 0.1

sources: VULMON: CVE-2023-1709 // NVD: CVE-2023-1709 // CNNVD: CNNVD-202304-1222

REFERENCES

url:https://cert-portal.siemens.com/productcert/html/ssa-629917.html

Trust: 1.7

url:https://www.cisa.gov/news-events/ics-advisories/icsa-23-103-11

Trust: 1.7

url:https://www.cisa.gov/news-events/ics-advisories/icsa-23-164-01

Trust: 1.6

url:https://www.auscert.org.au/bulletins/esb-2023.2160

Trust: 0.6

url:https://cxsecurity.com/cveshow/cve-2023-1709/

Trust: 0.6

url:https://cwe.mitre.org/data/definitions/121.html

Trust: 0.1

url:https://nvd.nist.gov

Trust: 0.1

sources: VULMON: CVE-2023-1709 // NVD: CVE-2023-1709 // CNNVD: CNNVD-202304-1222

SOURCES

db:VULMONid:CVE-2023-1709
db:NVDid:CVE-2023-1709
db:CNNVDid:CNNVD-202304-1222

LAST UPDATE DATE

2023-12-18T12:33:50.588000+00:00


SOURCES UPDATE DATE

db:VULMONid:CVE-2023-1709date:2023-06-07T00:00:00
db:NVDid:CVE-2023-1709date:2023-11-07T04:04:41.863
db:CNNVDid:CNNVD-202304-1222date:2023-06-15T00:00:00

SOURCES RELEASE DATE

db:VULMONid:CVE-2023-1709date:2023-06-07T00:00:00
db:NVDid:CVE-2023-1709date:2023-06-07T21:15:12.933
db:CNNVDid:CNNVD-202304-1222date:2023-04-14T00:00:00