Rewterz
Rewterz Threat Advisory – CVE-2021-20317 – Linux Kernel Vulnerability
September 28, 2021
Rewterz
Rewterz Threat Advisory – Multiple Cisco Products Vulnerabilities
September 29, 2021

Rewterz Threat Advisory – ICS: Multiple Siemens Solid Edge Vulnerabilities

Severity

High

Analysis Summary

CVE-2021-41540; CVE-2021-41539; CVE-2021-41537; CVE-2021-41536; CVE-2021-41535 

Siemens Solid Edge could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free flaw in the handling of OBJ files. By persuading a victim to open a specially-crafted OBJ file, an attacker could exploit this vulnerability to execute arbitrary code in the context of the current process.

CVE-2021-41538; CVE-2021-41533; CVE-2021-41534 

Siemens Solid Edge could allow a remote attacker to obtain sensitive information, caused by an unexpected access to an uninitialized pointer flaw in the handling of OBJ files. By persuading a victim to open a specially-crafted OBJ file, an attacker could exploit this vulnerability to obtain sensitive information in the context of the current process, and use this information to launch further attacks against the affected system.

Impact

  • Code Execution
  • Information Disclosure

Affected Vendors

  • Siemens

Affected Products

  • Siemens Solid Edge SE2021

Remediation

Refer to Siemens Security Advisory for patch, upgrade or suggested workaround information.

https://cert-portal.siemens.com/productcert/pdf/ssa-728618.pdf