Siemens has an update available to handle an out-of-bounds read vulnerability in its JT Open and JT Utilities, according to a report with CISA.

Successful exploitation of this vulnerability, discovered by Michael Heinzl, could allow an attacker to execute code in the context of the current process.

The following Siemens software suffers from the issue:

  • JT Open: All versions prior to V11.3.2.0
  • JT Utilities: All versions prior to V13.3.0.0

In the issue, the affected applications contain an out-of-bounds read vulnerability past the end of an allocated structure while parsing specially crafted JT files. This could allow an attacker to execute code in the context of the current process.

Schneider Bold

CVE-2023-29053 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.

The product sees use in multiple industrial sectors, and on a global basis.

No known public exploits specifically target this vulnerability. This vulnerability is not exploitable remotely. However, an attacker could leverage this low complexity vulnerability.

Siemens has identified the following specific workarounds and mitigations users can apply to reduce risk:

As a general security measure, Siemens recommends protecting network access to devices with appropriate mechanisms. To operate the devices in a protected IT environment, Siemens recommends configuring the environment according to Siemens’ operational guidelines for Industrial Security and following the recommendations in the product manuals.

For more information, click on Siemens security advisory SSA-642810.

ISSSource

Pin It on Pinterest

Share This