QID 591305
Date Published: 2023-01-31
QID 591305: Siemens J2TGo Multiple Vulnerabilities (SSA-360681)
Siemens JT2Go is affected by multiple out-of-bounds write vulnerabilities in the APDFL library from Datalogics. If a user is tricked to open a malicious PDF file with the affected products, this could lead the application to crash or potentially lead to arbitrary code execution.
AFFECTED PRODUCTS
JT2Go: All versions prior to V14.1.0.5
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys HKLM\SOFTWARE\Siemens\JT2Go.
Successful exploitation of this vulnerability could lead the application to crash or potentially lead to arbitrary code execution.
Solution
Customers are advised to refer to Schneider Electric MITIGATIONS section SSA-360681 for affected packages and patching details.
Vendor References
CVEs related to QID 591305
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| SSA-360681 |
|