An out-of-bounds write issue exists in the DWG file-reading procedure...
Vulnerability Description
An out-of-bounds write issue exists in the DWG file-reading procedure in the Drawings SDK (All versions prior to 2022.4) resulting from the lack of proper validation of user-supplied data. This can result in a write past the end of an allocated buffer and allow attackers to cause a denial-of-service condition or execute code in the context of the current process.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2021-32948
Credits & Attribution
No credits recorded in the NVD database.
References
- https://us-cert.cisa.gov/ics/advisories/icsa-21-159-02
- https://cert-portal.siemens.com/productcert/pdf/ssa-365397.pdf
- https://www.zerodayinitiative.com/advisories/ZDI-21-984/
- https://cert-portal.siemens.com/productcert/pdf/ssa-155599.pdf
- https://cert-portal.siemens.com/productcert/pdf/ssa-491245.pdf