VulnerabilityModified
CVE-2022-47967
A vulnerability has been identified in Solid Edge (All versions < V2023 MP1).
HIGH 7.8EPSS 0.28%
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (0.28%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A vulnerability has been identified in Solid Edge (All versions < V2023 MP1). The DOCMGMT.DLL contains a memory corruption vulnerability that could be triggered while parsing files in different file formats such as PAR, ASM, DFT. This could allow an attacker to execute code in the context of the current process.
- CVSS 3.1
- 7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 0.28% probability · 20th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119, CWE-787
- Affected
- siemens/solid edge
- Source
- productcert@siemens.com
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-997779.pdfMitigation, Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-997779.pdfMitigation, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.