CVE-2023-1709: Siemens JT2GO

High severity, CVSS 7.8. EPSS: 0.3% chance of exploitation in the next 30 days.

Datalogics Library APDFLThe v18.0.4PlusP1e and prior contains a stack-based buffer overflow due to documents containing corrupted fonts, which could allow an attack that causes an unhandled crash during the rendering process.

Affected products

  • Siemens JT2GO: before 14.2.0.2 (fixed in 14.2.0.2)
  • Siemens Teamcenter Visualization: from 13.2.0, before 13.2.0.13 (fixed in 13.2.0.13); from 13.3.0, before 13.3.0.9 (fixed in 13.3.0.9); from 14.0, before 14.0.0.5 (fixed in 14.0.0.5); from 14.1, before 14.1.0.7 (fixed in 14.1.0.7); from 14.2, before 14.2.0.2 (fixed in 14.2.0.2)

Published 2023-06-07. Last modified 2026-06-17.