Description
When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restrictions such as prohibiting an external DTD.
Published: 2021-05-27
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

No analysis available yet.

Remediation

No remediation available yet.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2021-14246 When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restrictions such as prohibiting an external DTD.
History

No history.

Subscriptions

Datakit Crosscadware
Luxion Keyshot
Siemens Solid Edge Se2020 Solid Edge Se2020 Firmware Solid Edge Se2021 Solid Edge Se2021 Firmware
cve-icon MITRE

Status: PUBLISHED

Assigner: icscert

Published:

Updated: 2024-08-03T21:26:08.955Z

Reserved: 2021-02-19T00:00:00.000Z

Link: CVE-2021-27492

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2021-05-27T16:15:08.050

Modified: 2024-11-21T05:58:05.993

Link: CVE-2021-27492

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses