QID 590802

QID 590802: Siemens Remote Connect Client Multiple Vulnerabilities (SSA-455843)

AFFECTED PRODUCTS
Siemens reports these vulnerabilities affect the following Simcenter Femap simulation applications:
Simcenter Femap: All versions prior to v2022.1

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Siemens using registry "HKLM\SOFTWARE\Siemens"

Successful exploitation of these vulnerabilities could allow an attacker to leverage the vulnerabilities to leak information or perform remote code execution in the context of the current process.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section SSA-455843 for affected packages and patching details.

    Software Advisories
    Advisory ID Software Component Link
    SSA-455843 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-455843.pdf