Lucene search

K
cveSiemensCVE-2022-34285
HistoryJul 12, 2022 - 10:15 a.m.

CVE-2022-34285

2022-07-1210:15:11
CWE-125
siemens
web.nvd.nist.gov
33
4
vulnerability
pads standard/plus viewer
cve-2022-34285
information leak
out of bounds read
fg-vd-22-050
nvd

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

23.4%

A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application is vulnerable to an out of bounds read past the end of an allocated buffer when parsing PCB files. An attacker could leverage this vulnerability to leak information in the context of the current process. (FG-VD-22-050)

Affected configurations

Nvd
Node
siemenspads_viewerplus
OR
siemenspads_viewerstandard
VendorProductVersionCPE
siemenspads_viewer*cpe:2.3:a:siemens:pads_viewer:*:*:*:*:plus:*:*:*
siemenspads_viewer*cpe:2.3:a:siemens:pads_viewer:*:*:*:*:standard:*:*:*

CNA Affected

[
  {
    "product": "PADS Standard/Plus Viewer",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  }
]

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

23.4%

Related for CVE-2022-34285