Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior lack proper validation of user-supplied data when parsing STP files. This could result in a stack-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process.
| Software | From | Fixed in |
|---|---|---|
| luxion / keyshot | - | 10.1.x |
| datakit / crosscadware | - | 2021.1.x |
| siemens / solid_edge_se2020_firmware | - | - |
| siemens / solid_edge_se2021_firmware | - | - |