CVE-2021-37176
Published on: 09/14/2021 12:00:00 AM UTC
Last Modified on: 09/23/2021 06:44:00 PM UTC
Certain versions of Simcenter Femap from Siemens contain the following vulnerability:
A vulnerability has been identified in Simcenter Femap V2020.2 (All versions), Simcenter Femap V2021.1 (All versions). The femap.exe application lacks proper validation of user-supplied data when parsing modfem files. This could result in an out of bounds read past the end of an allocated buffer. An attacker could leverage this vulnerability to leak information in the context of the current process. (ZDI-CAN-14260)
- CVE-2021-37176 has been assigned by
[email protected] to track the vulnerability - currently rated as LOW severity.
- Affected Vendor/Software:
Siemens - Simcenter Femap V2020.2 version All versions
- Affected Vendor/Software:
Siemens - Simcenter Femap V2021.1 version All versions
CVSS3 Score: 3.3 - LOW
Attack Vector ⓘ |
Attack Complexity |
Privileges Required |
User Interaction |
---|---|---|---|
LOCAL | LOW | NONE | REQUIRED |
Scope | Confidentiality Impact |
Integrity Impact |
Availability Impact |
UNCHANGED | LOW | NONE | NONE |
CVSS2 Score: 4.3 - MEDIUM
Access Vector ⓘ |
Access Complexity |
Authentication |
---|---|---|
NETWORK | MEDIUM | NONE |
Confidentiality Impact |
Integrity Impact |
Availability Impact |
PARTIAL | NONE | NONE |
CVE References
Description | Tags ⓘ | Link |
---|---|---|
ZDI-21-1073 | Zero Day Initiative | www.zerodayinitiative.com text/html |
![]() |
cert-portal.siemens.com application/pdf |
![]() |
There are currently no QIDs associated with this CVE
Known Affected Configurations (CPE V2.3)
Type | Vendor | Product | Version | Update | Edition | Language |
---|---|---|---|---|---|---|
Application | Siemens | Simcenter Femap | 2020.2 | - | All | All |
Application | Siemens | Simcenter Femap | 2021.1 | - | All | All |
- cpe:2.3:a:siemens:simcenter_femap:2020.2:-:*:*:*:*:*:*:
- cpe:2.3:a:siemens:simcenter_femap:2021.1:-:*:*:*:*:*:*:
No vendor comments have been submitted for this CVE
Social Mentions
Source | Title | Posted (UTC) |
---|---|---|
![]() |
CVE-2021-37176 : A vulnerability has been identified in Simcenter Femap V2020.2 All versions , Simcenter Femap V20… twitter.com/i/web/status/1… | 2021-09-14 10:59:02 |