Successful exploitation of these vulnerabilities could allow an attacker to execute code in the context of the current process. Trend Micro Zero Day Initiative reported these vulnerabilities to Siemens.
The following software from Siemens suffers from the vulnerabilities: Simcenter Femap, all versions prior to V2023.1.
In one issue, the affected application contains an out-of-bounds read past the end of an allocated structure while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.
CVE-2022-39157 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.
In addition, the affected application contains an out-of-bounds write past the end of an allocated buffer while parsing specially crafted X_T files. This could allow an attacker to execute code in the context of the current process.
CVE-2022-43397 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.8.
The product sees use mainly in the critical manufacturing sector, and on a global basis.
No known public exploits specifically target these vulnerabilities. These vulnerabilities are not exploitable remotely. However, an attacker with low skill level could leverage these low complexity vulnerabilities.
Siemens identified the following specific workarounds and mitigations users can apply to reduce risk:
- Simcenter Femap: Update to V2023.1 or a later version https://support.sw.siemens.com/
- Simcenter Femap: Avoid opening untrusted X_T files in Simcenter Femap
As a security measure, Siemens recommends users protect network access to devices with appropriate mechanisms. In order to operate the devices in a protected IT environment, Siemens recommends to configure the environment according to Siemens’ operational guidelines for Industrial Security.
Click here for more information on Siemens security advisory SSA-565356.

