HomeSecuritySiemens: Vulnerabilities in products allow arbitrary code execution!

Siemens: Product vulnerabilities allow arbitrary code execution!

Last week, Siemens informed its customers that some of its product development solutions are affected by twelve vulnerabilities, which hackers can exploit to execute arbitrary code with malicious files.

The vulnerabilities were discovered by a number of researchers and their disclosure was coordinated through Trend Micro's Zero Day Initiative (ZDI) and CISA, which published its own advisory. The affected products are developed by Siemens Digital Industries Software, which specializes in product lifecycle management (PLM) solutions.

Siemens: Product vulnerabilities allow arbitrary code execution!

Siemens and CISA have published an advisory for 18 vulnerabilities affecting Siemens JT2Go, a 3D viewer for JT data (a standard ISO 3D format), and Teamcenter Visualization, which provides organizations with visualization solutions for documents, 2D drawings and 3D models. In addition, a second advisory was published for six vulnerabilities affecting Siemens Solid Edge, a solution that provides software tools for 3D design, simulation and manufacturing.

Most vulnerabilities are of high severity and could lead to arbitrary code within the targeted process. One vulnerability could lead to information disclosure and has been rated as "medium" severity.

Additionally, code execution vulnerabilities are related to improper validation of user-supplied data when parsing certain file types, which leads to a memory corruption vulnerability. To carry out an attack, attackers must convince the target user to open a specially crafted file.

CISA

The file types that can be used to trigger the vulnerabilities are JT, CG4, CGM, PDF, RGB, TGA, PAR, ASM, PCX, SGI, and DFT. Although the description for all vulnerabilities is similar, a separate CVE identifier has been assigned to each variant of a vulnerability.

Siemens has started releasing patches for affected products. The German industrial giant has shared workarounds for versions that have not yet received fixes.

Siemens has also released some advisories describing vulnerabilities found in SCALANCE X industrial switches. These security holes, rated as “critical” and “high severity,” can expose the switches to DoS and man-in-the-middle attacks.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS