June 13, 2023, midnight |

Siemens ProductCERT Security Advisories cert-portal.siemens.com

Solid Edge is affected by a file parsing vulnerability in Drawings SDK from Open Design Alliance. If a user is tricked to open a malicious DWG file with any of the affected products, this could lead the application to crash or potentially lead to arbitrary code execution.


Siemens has released updates for the affected products and recommends to update to the latest versions.


Note:



  • This advisory covers security vulnerabilities recently disclosed by Open Design Alliance [0]


[0] https://www.opendesign.com/security-advisories

alliance application arbitrary code arbitrary code execution code code execution crash design dwg edge file malicious parsing products sdk siemens solid solid edge ssa vulnerability

More from cert-portal.siemens.com / Siemens ProductCERT Security Advisories

Cyber Security Network Engineer

@ Nine | North Sydney, Australia

Professional, IAM Security

@ Ingram Micro | Manila Shared Services Center

Principal Windows Threat & Detection Security Researcher (Cortex)

@ Palo Alto Networks | Tel Aviv-Yafo, Israel

Security Engineer - IT Infra Security Architecture

@ Coupang | Seoul, South Korea

Senior Security Engineer

@ LiquidX | Singapore, Central Singapore, Singapore

Application Security Engineer

@ Solidigm | Zapopan, Mexico