CVE-2021-32940
Description
An out-of-bounds read issue exists in the DWG file-recovering procedure in the Drawings SDK (All versions prior to 2022.5) resulting from the lack of proper validation of user-supplied data. This can result in a read past the end of an allocated buffer and allow attackers to cause a denial-of-service condition or read sensitive information from memory locations.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An out-of-bounds read in Open Design Alliance Drawings SDK prior to 2022.5 allows denial-of-service or information disclosure via crafted DWG files.
Vulnerability
The vulnerability is an out-of-bounds read in the DWG file-recovering procedure of Open Design Alliance Drawings SDK, all versions prior to 2022.5 [1]. The issue stems from insufficient validation of user-supplied data during parsing, leading to a read past the end of an allocated buffer [1][2].
Exploitation
An attacker can exploit this by convincing a user to open a specially crafted DWG file (e.g., via email or web link) [2]. No authentication is required, but user interaction is necessary [1][2]. The attack vector is local, with low complexity [1].
Impact
Successful exploitation can cause a denial-of-service condition or allow the attacker to read sensitive information from memory [1][2]. The CVSS v3 base score is 4.4 (AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:L) per CISA [1], or 3.3 per ZDI [2]. The read is limited to out-of-bounds memory, potentially leaking data.
Mitigation
Open Design Alliance released Drawings SDK version 2022.5 to address this vulnerability [1]. Users should update to the latest version. For Siemens JT2Go, apply vendor updates as recommended [2]. No workarounds are documented; the fix is to upgrade.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Drawings SDK/Drawings SDKdescription
- Range: <2022.5
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
4News mentions
0No linked articles in our index yet.