Vulnerability Details CVE-2021-32936
An out-of-bounds write issue exists in the DXF file-recovering procedure in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-supplied data. This can result in a write past the end of an allocated buffer and allow attackers to cause a denial-of-service condition or execute code in the context of the current process.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 38.8%
CVSS Severity
CVSS v3 Score 7.8
CVSS v2 Score 6.8
Products affected by CVE-2021-32936
-
cpe:2.3:a:opendesign:drawings_sdk:-
-
cpe:2.3:a:opendesign:drawings_sdk:2019
-
cpe:2.3:a:opendesign:drawings_sdk:2021.11
-
cpe:2.3:a:opendesign:drawings_sdk:2021.12
-
cpe:2.3:a:siemens:comos:-
-
cpe:2.3:a:siemens:comos:10.0
-
cpe:2.3:a:siemens:comos:10.0.3.0.18
-
cpe:2.3:a:siemens:comos:10.0.3.0.4
-
cpe:2.3:a:siemens:comos:10.0.3.1.40
-
cpe:2.3:a:siemens:comos:10.1
-
cpe:2.3:a:siemens:comos:10.1.0.0.2
-
cpe:2.3:a:siemens:comos:10.2
-
cpe:2.3:a:siemens:comos:10.3
-
cpe:2.3:a:siemens:comos:10.3.3.2.14
-
cpe:2.3:a:siemens:comos:10.3.3.3
-
cpe:2.3:a:siemens:comos:10.4
-
cpe:2.3:a:siemens:comos:9.1
-
cpe:2.3:a:siemens:comos:9.2
-
cpe:2.3:a:siemens:comos:9.2.0.6.10
-
cpe:2.3:a:siemens:comos:9.2.0.8.1
-
cpe:2.3:a:siemens:comos:9.2.6.36
-
cpe:2.3:a:siemens:jt2go:-
-
cpe:2.3:a:siemens:jt2go:13.1.0
-
cpe:2.3:a:siemens:jt2go:13.1.0.1
-
cpe:2.3:a:siemens:jt2go:13.1.0.2
-
cpe:2.3:a:siemens:jt2go:13.1.0.3
-
cpe:2.3:a:siemens:jt2go:13.2.0
-
cpe:2.3:a:siemens:teamcenter_visualization:-
-
cpe:2.3:a:siemens:teamcenter_visualization:12.4.0
-
cpe:2.3:a:siemens:teamcenter_visualization:13.0.0
-
cpe:2.3:a:siemens:teamcenter_visualization:13.1.0
-
cpe:2.3:a:siemens:teamcenter_visualization:13.1.0.1
-
cpe:2.3:a:siemens:teamcenter_visualization:13.1.0.2
-
cpe:2.3:a:siemens:teamcenter_visualization:13.1.0.3
-
cpe:2.3:a:siemens:teamcenter_visualization:13.2.0
-
cpe:2.3:a:siemens:teamcenter_visualization:8.0.9085