Lucene search

K
cvelistIcscertCVELIST:CVE-2021-27492
HistoryMay 27, 2021 - 3:41 p.m.

CVE-2021-27492

2021-05-2715:41:49
CWE-611
icscert
www.cve.org

5.8 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.2%

When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restrictions such as prohibiting an external DTD.

CNA Affected

[
  {
    "product": "Datakit Software libraries embedded in Luxion KeyShot software",
    "vendor": "n/a",
    "versions": [
      {
        "status": "affected",
        "version": "CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior"
      }
    ]
  }
]

5.8 Medium

AI Score

Confidence

High

0.004 Low

EPSS

Percentile

73.2%

Related for CVELIST:CVE-2021-27492