High severity7.8NVD Advisory· Published Nov 14, 2021· Updated Jun 17, 2026
CVE-2021-43336
CVE-2021-43336
Description
An Out-of-Bounds Write vulnerability exists when reading a DXF or DWG file using Open Design Alliance Drawings SDK before 2022.11. The specific issue exists within the parsing of DXF and DWG files. Crafted data in a DXF or DWG file (an invalid number of properties) can trigger a write operation past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
7- cpe:2.3:a:opendesign:drawings_software_development_kit:*:*:*:*:*:*:*:*Range: <2022.11
- cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*
- cpe:2.3:a:siemens:solid_edge:se2022:-:*:*:*:*:*:*
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*range: >=12.4.0,<12.4.0.13
- cpe:2.3:a:siemens:teamcenter_visualization:13.1.0:*:*:*:*:*:*:*
- Open Design Alliance/Drawings SDKdescription
- Range: <2022.11
Patches
Vulnerability mechanics
References
4- cert-portal.siemens.com/productcert/pdf/ssa-301589.pdfnvdThird Party Advisory
- cert-portal.siemens.com/productcert/pdf/ssa-491245.pdfnvdThird Party Advisory
- www.opendesign.com/security-advisoriesnvdVendor Advisory
- www.zerodayinitiative.com/advisories/ZDI-22-334/nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.