Rewterz
Rewterz Threat Advisory – ICS: Multiple Siemens JT2Go and Teamcenter Visualization Vulnerabilities
May 11, 2022
Rewterz
Rewterz Threat Alert – APT36 Crimson RAT – Active IOCs
May 11, 2022

Rewterz Threat Advisory – ICS: Siemens Teamcenter XML external entity Vulnerability

Severity

Medium

Analysis Summary

CVE-2022-29801

Siemens Teamcenter is vulnerable to an XML external entity injection (XXE) attack when processing XML data, caused by a weakly configured XML parser. By persuading a victim to use specially-crafted XML content, a remote attacker could exploit this vulnerability to read arbitrary files.

Impact

  • Unauthorized Access

Indicators Of Compromise

CVE

  • CVE-2022-29801

Affected Vendors

  • Siemens

Affected Products

  • Siemens Teamcenter 12.4
  • Siemens Teamcenter 13.0
  • Siemens Teamcenter 13.1
  • Siemens Teamcenter 13.2
  • Siemens Teamcenter 13.3
  • Siemens Teamcenter 14.0

Remediation

Refer to Siemens Security Advisory for patch, upgrade or suggested workaround information.

Siemens Security Advisory