High severity7.8NVD Advisory· Published Nov 8, 2022· Updated Jun 17, 2026
CVE-2022-41663
CVE-2022-41663
Description
A vulnerability has been identified in JT2Go (All versions < V14.1.0.4), Teamcenter Visualization V13.2 (All versions < V13.2.0.12), Teamcenter Visualization V13.3 (All versions < V13.3.0.7), Teamcenter Visualization V14.0 (All versions < V14.0.0.3), Teamcenter Visualization V14.1 (All versions < V14.1.0.4). The affected applications contain a use-after-free vulnerability that could be triggered while parsing specially crafted CGM files. An attacker could leverage this vulnerability to execute code in the context of the current process.
Affected products
9cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:siemens:jt2go:*:*:*:*:*:*:*:*range: <14.1.0.4
- (no CPE)range: <V14.1.0.4
- (no CPE)range: All versions < V14.1.0.4
cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*+ 5 more
- cpe:2.3:a:siemens:teamcenter_visualization:*:*:*:*:*:*:*:*range: >=13.3.0,<13.3.0.7
- (no CPE)range: <V13.2.0.12, <V13.3.0.7, <V14.0.0.3, <V14.1.0.4
- (no CPE)range: All versions < V13.2.0.12
- (no CPE)range: All versions < V13.3.0.7
- (no CPE)range: All versions < V14.0.0.3
- (no CPE)range: All versions < V14.1.0.4
Patches
Vulnerability mechanics
References
1- cert-portal.siemens.com/productcert/pdf/ssa-120378.pdfnvdVendor Advisory
News mentions
0No linked articles in our index yet.