VYPR
High severity7.8NVD Advisory· Published Sep 13, 2022· Updated Jun 17, 2026

CVE-2022-39147

CVE-2022-39147

Description

A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.262), Parasolid V33.1 (All versions >= V33.1.262 < V33.1.263), Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.161), Parasolid V35.0 (All versions >= V35.0.161 < V35.0.164), Simcenter Femap V2022.1 (All versions < V2022.1.3), Simcenter Femap V2022.2 (All versions < V2022.2.2). The affected application is vulnerable to uninitialized pointer access while parsing specially crafted X_T files. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-17506)

Affected products

10
  • cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:*range: >=33.1,<33.1.263
    • (no CPE)range: < V33.1.262, >= V33.1.262 < V33.1.263, < V34.0.252, < V34.1.242, < V35.0.161, >= V35.0.161 < V35.0.164
    • (no CPE)range: All versions >= V33.1.262 < V33.1.263
    • (no CPE)range: All versions < V34.0.252
    • (no CPE)range: All versions < V34.1.242
    • (no CPE)range: All versions >= V35.0.161 < V35.0.164
  • cpe:2.3:a:siemens:simcenter_femap:*:*:*:*:*:*:*:*
    Range: >=2022.1,<2022.1.3
  • Siemens Foundation/Femapllm-fuzzy3 versions
    V2022.1 < V2022.1.3, V2022.2 < V2022.2.2+ 2 more
    • (no CPE)range: V2022.1 < V2022.1.3, V2022.2 < V2022.2.2
    • (no CPE)range: All versions < V2022.1.3
    • (no CPE)range: All versions < V2022.2.2

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.