CVE-2022-43397: Siemens Parasolid
High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.
A vulnerability has been identified in Parasolid V34.0 (All versions < V34.0.252), Parasolid V34.1 (All versions < V34.1.242), Parasolid V35.0 (All versions < V35.0.170), Simcenter Femap (All versions < V2023.1). The affected application contains an out of bounds write past the end of an allocated buffer while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-17854)
Affected products
- Siemens Parasolid: from 34.0, before 34.0.252 (fixed in 34.0.252); from 34.1, before 34.1.242 (fixed in 34.1.242); from 35.0, before 35.0.170 (fixed in 35.0.170)
Published 2022-11-08. Last modified 2026-06-17.