CVE-2021-27492
Last modified
CVE-2021-27492 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restrictions such as prohibiting an external DTD.. EPSS estimates a 1.75% chance of exploitation in the next 30 days.
Description
When opening a specially crafted 3DXML file, the application containing Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, Step3dRead, Ug3dReadPsr, Jt3dReadPsr modules in KeyShot Versions v10.1 and prior could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restrictions such as prohibiting an external DTD.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Datakit | Crosscadware | <= 2021.1 |
| Luxion | Keyshot | <= 10.1 |
| Siemens | Solid Edge Se2020 Firmware | All versions |
| Siemens | Solid Edge Se2021 Firmware | All versions |
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-119468.pdfThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-145-01Third Party Advisory, US Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-21-567/Third Party Advisory, VDB Entry
- https://cert-portal.siemens.com/productcert/pdf/ssa-119468.pdfThird Party Advisory
- https://us-cert.cisa.gov/ics/advisories/icsa-21-145-01Third Party Advisory, US Government Resource
- https://www.zerodayinitiative.com/advisories/ZDI-21-567/Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2021-27492?
How severe is CVE-2021-27492?
How do I fix CVE-2021-27492?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2021
- CVE-2021-27486FATEK Automation WinProladder Versions 3.30 and prior is vul…7.8
- CVE-2021-27487ZOLL Defibrillator Dashboard, v prior to 2.2, The affected p…5.5
- CVE-2021-27488Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, S…7.8
- CVE-2021-27489ZOLL Defibrillator Dashboard, v prior to 2.2, The web applic…8.8
- CVE-2021-27490Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, S…7.8
- CVE-2021-27491Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed myli…7.5
- CVE-2021-27493Philips Vue PACS versions 12.2.x.x and prior does not ensure…6.5
- CVE-2021-27494Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, S…7.8
- CVE-2021-27495Ypsomed mylife Cloud, mylife Mobile Application:Ypsomed myli…7.1
- CVE-2021-27496Datakit Software libraries CatiaV5_3dRead, CatiaV6_3dRead, S…7.8
- CVE-2021-27497Philips Vue PACS versions 12.2.x.x and prior does not use or…9.8
- CVE-2021-27498A specifically crafted packet sent by an attacker to EIPStac…7.5
Are you affected by CVE-2021-27492?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
