Vulnerability Description
Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 have multiple NULL pointer dereference issues while processing project files, which may allow an attacker to execute arbitrary code.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Luxion | Keyshot | < 10.1 |
| Luxion | Keyshot Network Rendering | < 10.1 |
| Luxion | Keyshot Viewer | < 10.1 |
| Luxion | Keyvr | < 10.1 |
| Siemens | Solid Edge Se2020 Firmware | All versions |
| Siemens | Solid Edge Se2020 | - |
| Siemens | Solid Edge Se2021 Firmware | All versions |
| Siemens | Solid Edge Se2021 | - |
Related Weaknesses (CWE)
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-231216.pdfThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-035-01Third Party AdvisoryUS Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-21-317/Third Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-21-325/Third Party AdvisoryVDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-231216.pdfThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-035-01Third Party AdvisoryUS Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-21-317/Third Party AdvisoryVDB Entry
- https://www.zerodayinitiative.com/advisories/ZDI-21-325/Third Party AdvisoryVDB Entry
FAQ
What is CVE-2021-22649?
CVE-2021-22649 is a vulnerability with a CVSS score of 7.8 (HIGH). Luxion KeyShot versions prior to 10.1, Luxion KeyShot Viewer versions prior to 10.1, Luxion KeyShot Network Rendering versions prior to 10.1, and Luxion KeyVR versions prior to 10.1 have multiple NULL...
How severe is CVE-2021-22649?
CVE-2021-22649 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2021-22649?
Check the references section above for vendor advisories and patch information. Affected products include: Luxion Keyshot, Luxion Keyshot Network Rendering, Luxion Keyshot Viewer, Luxion Keyvr, Siemens Solid Edge Se2020 Firmware.