{ "data_version": "4.0", "data_type": "CVE", "data_format": "MITRE", "CVE_data_meta": { "ID": "CVE-2022-3159", "ASSIGNER": "ics-cert@hq.dhs.gov", "STATE": "PUBLIC" }, "description": { "description_data": [ { "lang": "eng", "value": "The APDFL.dll contains a stack-based buffer overflow vulnerability that could be triggered while parsing specially crafted PDF files. This could allow an attacker to execute code in the context of the current process." } ] }, "problemtype": { "problemtype_data": [ { "description": [ { "lang": "eng", "value": "CWE-121 ", "cweId": "CWE-121" } ] } ] }, "affects": { "vendor": { "vendor_data": [ { "vendor_name": "Siemens\u00a0", "product": { "product_data": [ { "product_name": "JT2Go", "version": { "version_data": [ { "version_value": "0", "version_affected": "=" } ] } }, { "product_name": "Teamcenter Visualization V13.3", "version": { "version_data": [ { "version_value": "0", "version_affected": "=" } ] } }, { "product_name": "Teamcenter Visualization V14.0", "version": { "version_data": [ { "version_value": "0", "version_affected": "=" } ] } }, { "product_name": "Teamcenter Visualization V14.1", "version": { "version_data": [ { "version_value": "0", "version_affected": "=" } ] } } ] } } ] } }, "references": { "reference_data": [ { "url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-349-15", "refsource": "MISC", "name": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-349-15" }, { "url": "https://cert-portal.siemens.com/productcert/html/ssa-360681.html", "refsource": "MISC", "name": "https://cert-portal.siemens.com/productcert/html/ssa-360681.html" }, { "url": "https://cert-portal.siemens.com/productcert/csaf/ssa-360681.json", "refsource": "MISC", "name": "https://cert-portal.siemens.com/productcert/csaf/ssa-360681.json" } ] }, "generator": { "engine": "Vulnogram 0.1.0-dev" }, "source": { "discovery": "EXTERNAL" }, "work_around": [ { "lang": "en", "supportingMedia": [ { "base64": false, "type": "text/html", "value": "\n
Siemens identified the following specific workaround and mitigation user can apply to reduce risk:
\n\nAs a general security measure, Siemens recommends protecting \nnetwork access to devices with appropriate mechanisms. To operate the \ndevices in a protected IT environment, Siemens recommends configuring \nthe environment according to Siemens' operational guidelines for industrial security
and following the recommendations in the product manuals. Siemens also provides additional information on industrial security.