QID 591106

Date Published: 2022-10-18

QID 591106: Siemens Simcenter Femap File Parsing Multiple Vulnerabilities (SSA-518824) (icsa-22-258-02)

AFFECTED PRODUCTS
Simcenter Femap, a modeling and simulation software V2022.1: All versions prior to V2022.1.3
Simcenter Femap, a modeling and simulation software V2022.2: All versions prior to V2022.2.2

QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys

Successful exploitation of these vulnerabilities could result in remote code execution in the compromised process.

  • CVSS V3 rated as High - 7.8 severity.
  • CVSS V2 rated as Low - 0 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section ssa-518824 for affected packages and patching details.

    Software Advisories
    Advisory ID Software Component Link
    icsa-22-258-02 URL Logo www.cisa.gov/uscert/ics/advisories/icsa-22-258-02
    ssa-518824 URL Logo cert-portal.siemens.com/productcert/pdf/ssa-518824.pdf