Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2021-24857 | The Datalogics APDFL library used in affected products is vulnerable to memory corruption condition while parsing specially crafted PDF files. An attacker could leverage this vulnerability to execute code in the context of the current process. |
Solution
Siemens has released updates for some of the affected products and recommends updating to the latest versions. Siemens is preparing further updates and recommends specific countermeasures for products where updates are not yet available. * JT2Go: Update to v13.2.0.7 https://www.plm.automation.siemens.com/global/en/products/plm-components/jt2go.html or later version * Teamcenter Visualization v13.1: Update to v13.1.0.9 or later version https://support.sw.siemens.com/ * Teamcenter Visualization v13.2: Update to v13.2.0.7 or later version https://support.sw.siemens.com/ * Teamcenter Visualization v13.3: Update to v13.3.0.1 or later version https://support.sw.siemens.com/ Please see Siemens security advisory SSA-301589 https://cert-portal.siemens.com/productcert/pdf/ssa-301589.pdf for more information.
Workaround
Siemens has identified the following specific workarounds and mitigations users can apply to reduce the risk: * Avoid opening untrusted files from unknown sources in affected products. As a general security measure, Siemens strongly recommends protecting network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ operational guidelines for industrial security https://cert-portal.siemens.com/operational-guidelines-industrial-security.pdf , and to follow the recommendations in the product manuals. Additional information on industrial security by Siemens can be found on the Siemens industrial security webpage https://www.siemens.com/industrialsecurity . Please see Siemens security advisory SSA-301589 https://cert-portal.siemens.com/productcert/pdf/ssa-301589.pdf for more information.
No history.
Status: PUBLISHED
Assigner: icscert
Published:
Updated: 2024-08-04T01:37:16.588Z
Reserved: 2021-08-10T19:21:41.085Z
Link: CVE-2021-38405
No data.
Status : Modified
Published: 2023-11-21T19:15:07.647
Modified: 2024-11-21T06:17:01.010
Link: CVE-2021-38405
No data.
OpenCVE Enrichment
No data.
EUVD