Vulnerability Details CVE-2021-25178
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A stack-based buffer overflow vulnerability exists when the recover operation is run with malformed .DXF and .DWG files. This can allow attackers to cause a crash potentially enabling a denial of service attack (Crash, Exit, or Restart) or possible code execution.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.009
EPSS Ranking 74.5%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2021-25178
-
cpe:2.3:a:opendesign:drawings_software_development_kit:*
-
cpe:2.3:a:siemens:comos:-
-
cpe:2.3:a:siemens:comos:10.0
-
cpe:2.3:a:siemens:comos:10.0.3.0.18
-
cpe:2.3:a:siemens:comos:10.0.3.0.4
-
cpe:2.3:a:siemens:comos:10.0.3.1.40
-
cpe:2.3:a:siemens:comos:10.1
-
cpe:2.3:a:siemens:comos:10.1.0.0.2
-
cpe:2.3:a:siemens:comos:10.2
-
cpe:2.3:a:siemens:comos:10.3
-
cpe:2.3:a:siemens:comos:10.3.3.2.14
-
cpe:2.3:a:siemens:comos:10.3.3.3
-
cpe:2.3:a:siemens:comos:10.4
-
cpe:2.3:a:siemens:comos:9.1
-
cpe:2.3:a:siemens:comos:9.2
-
cpe:2.3:a:siemens:comos:9.2.0.6.10
-
cpe:2.3:a:siemens:comos:9.2.0.8.1
-
cpe:2.3:a:siemens:comos:9.2.6.36
-
cpe:2.3:a:siemens:jt2go:-
-
cpe:2.3:a:siemens:jt2go:13.1.0
-
cpe:2.3:a:siemens:teamcenter_visualization:-
-
cpe:2.3:a:siemens:teamcenter_visualization:12.4.0
-
cpe:2.3:a:siemens:teamcenter_visualization:13.0.0
-
cpe:2.3:a:siemens:teamcenter_visualization:13.1.0
-
cpe:2.3:a:siemens:teamcenter_visualization:8.0.9085