Vulnerability Description
Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to an attack because the .bip documents display a “load” command, which can be pointed to a .dll from a remote network share. As a result, the .dll entry point can be executed without sufficient UI warning.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Luxion | Keyshot | < 10.1 |
| Luxion | Keyshot Network Rendering | < 10.1 |
| Luxion | Keyshot Viewer | < 10.1 |
| Luxion | Keyvr | < 10.1 |
| Siemens | Solid Edge Se2020 Firmware | All versions |
| Siemens | Solid Edge Se2020 | - |
| Siemens | Solid Edge Se2021 Firmware | All versions |
| Siemens | Solid Edge Se2021 | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-231216.pdfThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-035-01Third Party AdvisoryUS Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-21-323/Third Party AdvisoryVDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-231216.pdfThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-035-01Third Party AdvisoryUS Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-21-323/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2021-22645?
CVE-2021-22645 is a vulnerability with a CVSS score of 7.8 (HIGH). Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 are vulnerable to ...
How severe is CVE-2021-22645?
CVE-2021-22645 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22645?
Check the references section above for vendor advisories and patch information. Affected products include: Luxion Keyshot, Luxion Keyshot Network Rendering, Luxion Keyshot Viewer, Luxion Keyvr, Siemens Solid Edge Se2020 Firmware.