Lucene search

K
nvd[email protected]NVD:CVE-2021-27040
HistoryJun 25, 2021 - 1:15 p.m.

CVE-2021-27040

2021-06-2513:15:08
CWE-125
web.nvd.nist.gov
3
dwg file
read boundaries
arbitrary code
exploit

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

EPSS

0.002

Percentile

59.6%

A maliciously crafted DWG file can be forced to read beyond allocated boundaries when parsing the DWG file. This vulnerability can be exploited to execute arbitrary code.

Affected configurations

Nvd
Node
autodeskadvance_steelRange20192019.1.3
OR
autodeskadvance_steelRange20202020.1.4
OR
autodeskadvance_steelRange20212021.1.1
OR
autodeskadvance_steelRange20222022.0.1
OR
autodeskautocadRange20192019.1.3
OR
autodeskautocadRange20202020.1.4
OR
autodeskautocadRange20212021.1.1
OR
autodeskautocadRange20222022.0.1
OR
autodeskautocad_architectureRange20192019.1.3
OR
autodeskautocad_architectureRange20202020.1.4
OR
autodeskautocad_architectureRange20212021.1.1
OR
autodeskautocad_architectureRange20222022.0.1
OR
autodeskautocad_electricalRange20192019.1.3
OR
autodeskautocad_electricalRange20202020.1.4
OR
autodeskautocad_electricalRange20212021.1.1
OR
autodeskautocad_electricalRange20222022.0.1
OR
autodeskautocad_ltRange20192019.1.3
OR
autodeskautocad_ltRange20202020.1.4
OR
autodeskautocad_ltRange20212021.1.1
OR
autodeskautocad_ltRange20222022.0.1
OR
autodeskautocad_map_3dRange20192019.1.3
OR
autodeskautocad_map_3dRange20202020.1.4
OR
autodeskautocad_map_3dRange20212021.1.1
OR
autodeskautocad_map_3dRange20222022.0.1
OR
autodeskautocad_mechanicalRange20192019.1.3
OR
autodeskautocad_mechanicalRange20202020.1.4
OR
autodeskautocad_mechanicalRange20212021.1.1
OR
autodeskautocad_mechanicalRange20222022.0.1
OR
autodeskautocad_mepRange20192019.1.3
OR
autodeskautocad_mepRange20202020.1.4
OR
autodeskautocad_mepRange20212021.1.1
OR
autodeskautocad_mepRange20222022.0.1
OR
autodeskautocad_plant_3dRange20192019.1.3
OR
autodeskautocad_plant_3dRange20202020.1.4
OR
autodeskautocad_plant_3dRange20212021.1.1
OR
autodeskautocad_plant_3dRange20222022.0.1
OR
autodeskcivil_3dRange20192019.1.3
OR
autodeskcivil_3dRange20202020.1.4
OR
autodeskcivil_3dRange20212021.1.1
OR
autodeskcivil_3dRange20222022.0.1
OR
autodeskdwg_trueviewRange20222022.1.1
Node
iconicsgenesis64Range10.97
Node
mitsubishielectricmc_works64Range4.04e
VendorProductVersionCPE
autodeskadvance_steel*cpe:2.3:a:autodesk:advance_steel:*:*:*:*:*:*:*:*
autodeskautocad*cpe:2.3:a:autodesk:autocad:*:*:*:*:*:*:*:*
autodeskautocad_architecture*cpe:2.3:a:autodesk:autocad_architecture:*:*:*:*:*:*:*:*
autodeskautocad_electrical*cpe:2.3:a:autodesk:autocad_electrical:*:*:*:*:*:*:*:*
autodeskautocad_lt*cpe:2.3:a:autodesk:autocad_lt:*:*:*:*:*:*:*:*
autodeskautocad_map_3d*cpe:2.3:a:autodesk:autocad_map_3d:*:*:*:*:*:*:*:*
autodeskautocad_mechanical*cpe:2.3:a:autodesk:autocad_mechanical:*:*:*:*:*:*:*:*
autodeskautocad_mep*cpe:2.3:a:autodesk:autocad_mep:*:*:*:*:*:*:*:*
autodeskautocad_plant_3d*cpe:2.3:a:autodesk:autocad_plant_3d:*:*:*:*:*:*:*:*
autodeskcivil_3d*cpe:2.3:a:autodesk:civil_3d:*:*:*:*:*:*:*:*
Rows per page:
1-10 of 131

CVSS2

4.3

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

CVSS3

3.3

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

EPSS

0.002

Percentile

59.6%

Related for NVD:CVE-2021-27040