CVE-2023-33123: Siemens JT2GO

High severity, CVSS 7.8. EPSS: 0.2% chance of exploitation in the next 30 days.

A vulnerability has been identified in JT2Go (All versions < V14.2.0.3), Teamcenter Visualization V13.2 (All versions < V13.2.0.13), Teamcenter Visualization V13.3 (All versions < V13.3.0.10), Teamcenter Visualization V14.0 (All versions < V14.0.0.6), Teamcenter Visualization V14.1 (All versions < V14.1.0.8), Teamcenter Visualization V14.2 (All versions < V14.2.0.3). The affected applications contain an out of bounds read past the end of an allocated structure while parsing specially crafted CGM files. This could allow an attacker to execute code in the context of the current process.

Affected products

  • Siemens JT2GO: before 14.2.0.3 (fixed in 14.2.0.3)
  • Siemens Teamcenter Visualization: from 13.2.0, before 13.2.0.13 (fixed in 13.2.0.13); from 13.3.0, before 13.3.0.10 (fixed in 13.3.0.10); from 14.0, before 14.0.0.6 (fixed in 14.0.0.6); from 14.1, before 14.1.0.8 (fixed in 14.1.0.8); from 14.2, before 14.2.0.3 (fixed in 14.2.0.3)

Published 2023-06-13. Last modified 2026-06-17.