CVE-2023-38072: Siemens JT2GO
High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.
A vulnerability has been identified in JT2Go (All versions < V14.3.0.1), Teamcenter Visualization V13.3 (All versions < V13.3.0.12), Teamcenter Visualization V14.0 (All versions), Teamcenter Visualization V14.1 (All versions < V14.1.0.11), Teamcenter Visualization V14.2 (All versions < V14.2.0.6), Teamcenter Visualization V14.3 (All versions < V14.3.0.1), Tecnomatix Plant Simulation V2201 (All versions < V2201.0010), Tecnomatix Plant Simulation V2302 (All versions < V2302.0004). The affected application contains an out of bounds write past the end of an allocated structure while parsing specially crafted WRL files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-20825)
Affected products
- Siemens JT2GO: before 14.3.0.1 (fixed in 14.3.0.1)
- Siemens Teamcenter Visualization: from 13.3.0, before 13.4.0.12 (fixed in 13.4.0.12); from 14.0, before 14.1.0.11 (fixed in 14.1.0.11); from 14.2, before 14.2.0.6 (fixed in 14.2.0.6); from 14.3, before 14.3.0.1 (fixed in 14.3.0.1)
- Siemens Tecnomatix Plant Simulation: from 2201.0, before 2201.0010 (fixed in 2201.0010); from 2302.0, before 2302.0004 (fixed in 2302.0004)
Published 2023-09-12. Last modified 2026-06-17.