CVE-2021-25175
Description
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Conversion issue exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
A type conversion vulnerability in Open Design Alliance Drawings SDK before 2021.11 allows remote code execution via malformed DXF/DWG files when parsed by applications like Siemens JT2Go.
Vulnerability
The vulnerability is a type conversion issue in the Open Design Alliance Drawings SDK prior to version 2021.11. When rendering malformed .DXF or .DWG files, the SDK fails to properly validate user-supplied data, leading to a write past the end of an allocated buffer. This affects all versions before 2021.11. The issue is present in the DXF/DWG parsing component. [1][2][3][4]
Exploitation
An attacker can exploit this by crafting a malicious .DXF or .DWG file and convincing a user to open it with an application that uses the vulnerable SDK, such as Siemens JT2Go. No authentication is required, but user interaction is necessary. The attacker does not need any special network position; the file can be delivered via email, web download, etc. The specific flaw is triggered during parsing of the malformed file, causing an out-of-bounds write. [2][3][4]
Impact
Successful exploitation allows an attacker to execute arbitrary code in the context of the current process. This can lead to complete compromise of the affected system, including confidentiality, integrity, and availability. The CVSS score is 7.8 (High). [2][3][4]
Mitigation
The vendor, Open Design Alliance, fixed the issue in Drawings SDK version 2021.11. Users should update to that version or later. For Siemens JT2Go, users should apply the latest updates from Siemens. No workarounds are mentioned in the references. [1][2][3][4]
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Open Design Alliance/Drawings SDKdescription
- Range: <2021.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
9- cert-portal.siemens.com/productcert/pdf/ssa-155599.pdfmitrex_refsource_CONFIRM
- cert-portal.siemens.com/productcert/pdf/ssa-663999.pdfmitrex_refsource_CONFIRM
- www.opendesign.com/security-advisoriesmitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-21-218/mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-21-223/mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-21-224/mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-21-244/mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-21-245/mitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-21-246/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.