VYPR
Unrated severityNVD Advisory· Published Jun 17, 2021· Updated Aug 3, 2024

CVE-2021-32938

CVE-2021-32938

Description

Drawings SDK (All versions prior to 2022.4) are vulnerable to an out-of-bounds read due to parsing of DWG files resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer and allows attackers to cause a denial-of service condition or read sensitive information from memory.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An out-of-bounds read in Open Design Alliance Drawings SDK prior to 2022.4 allows denial of service or information disclosure via crafted DWG files.

Vulnerability

An out-of-bounds read vulnerability exists in Open Design Alliance Drawings SDK versions prior to 2022.4 when parsing specially crafted DWG files. The issue stems from insufficient validation of user-supplied data, leading to a read past the end of an allocated buffer [1][2]. This affects all products that incorporate the SDK, such as Siemens JT2Go [2].

Exploitation

Exploitation requires user interaction: the victim must open a malicious DWG file or visit a page that triggers parsing via an application using the vulnerable SDK [2]. An attacker with local access can craft a DWG file that, when processed, triggers the out-of-bounds read. No authentication is needed, but the user must be tricked into opening the file [1].

Impact

Successful exploitation can cause a denial-of-service condition or allow the attacker to read sensitive information from memory [1]. The ZDI advisory notes that this flaw can be leveraged in conjunction with other vulnerabilities to achieve arbitrary code execution in the context of the current process [2]. The CVSS v3 base score is 4.4 (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L) per CISA [1].

Mitigation

Upgrade to Drawings SDK version 2022.4 or later, which contains the fix [1]. For users of Siemens JT2Go, apply the vendor-supplied update as recommended in the ZDI advisory [2]. No workarounds are documented. This vulnerability is not listed on the CISA Known Exploited Vulnerabilities (KEV) catalog as of the publication date.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

5

News mentions

0

No linked articles in our index yet.