Vulnerability Database

289,784

Total vulnerabilities in the database

CVE-2023-49125

A vulnerability has been identified in Parasolid V35.0 (All versions < V35.0.263), Parasolid V35.1 (All versions < V35.1.252), Parasolid V36.0 (All versions < V36.0.198), Solid Edge SE2023 (All versions < V223.0 Update 11), Solid Edge SE2024 (All versions < V224.0 Update 3). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted files containing XT format. This could allow an attacker to execute code in the context of the current process.

  • Published: Feb 13, 2024
  • Updated: May 16, 2024
  • CVE: CVE-2023-49125
  • Severity: High
  • Exploit:

CVSS v3:

  • Severity: High
  • Score: 7.8
  • AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CWEs:

Software From Fixed in
siemens / solid_edge_se2023 223.0-update_0004 223.0-update_0004.x
siemens / solid_edge_se2023 223.0-update_0005 223.0-update_0005.x
siemens / solid_edge_se2023 223.0-update_0006 223.0-update_0006.x
siemens / solid_edge_se2023 223.0-update_0007 223.0-update_0007.x
siemens / solid_edge_se2023 223.0-update_0008 223.0-update_0008.x
siemens / solid_edge_se2023 223.0-update_0009 223.0-update_0009.x
siemens / solid_edge_se2024 - 224.0
siemens / solid_edge_se2024 224.0-update_0002 224.0-update_0002.x
siemens / solid_edge_se2024 224.0-update_0001 224.0-update_0001.x
siemens / solid_edge_se2023 223.0-update_0010 223.0-update_0010.x
siemens / parasolid 36.0 36.0.198
siemens / parasolid 35.1 35.1.252
siemens / parasolid 35.0 35.0.263
siemens / solid_edge_se2023 223.0-update_0003 223.0-update_0003.x
siemens / solid_edge_se2023 223.0-update_0002 223.0-update_0002.x
siemens / solid_edge_se2023 223.0-update_0001 223.0-update_0001.x
siemens / solid_edge_se2023 - 223.0