Lucene search

K
cveSiemensCVE-2022-34288
HistoryJul 12, 2022 - 10:15 a.m.

CVE-2022-34288

2022-07-1210:15:11
CWE-125
siemens
web.nvd.nist.gov
36
4
vulnerability
pads standard/plus viewer
buffer overflow
out of bounds read
information leakage
cve-2022-34288

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

23.4%

A vulnerability has been identified in PADS Standard/Plus Viewer (All versions). The affected application is vulnerable to an out of bounds read past the end of an allocated buffer when parsing PCB files. An attacker could leverage this vulnerability to leak information in the context of the current process. (FG-VD-22-053)

Affected configurations

Nvd
Node
siemenspads_viewerplus
OR
siemenspads_viewerstandard
VendorProductVersionCPE
siemenspads_viewer*cpe:2.3:a:siemens:pads_viewer:*:*:*:*:plus:*:*:*
siemenspads_viewer*cpe:2.3:a:siemens:pads_viewer:*:*:*:*:standard:*:*:*

CNA Affected

[
  {
    "product": "PADS Standard/Plus Viewer",
    "vendor": "Siemens",
    "versions": [
      {
        "status": "affected",
        "version": "All versions"
      }
    ]
  }
]

Social References

More

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

5.2

Confidence

High

EPSS

0.001

Percentile

23.4%

Related for CVE-2022-34288