CVE-2022-34661
Last modified
CVE-2022-34661 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.5), Teamcenter V14.0 (All versions < V14.0.0.2). File Server Cache service in Teamcenter is vulnerable to denial of service by entering infinite loops and using up CPU cycles. EPSS estimates a 0.64% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.15), Teamcenter V13.0 (All versions < V13.0.0.10), Teamcenter V13.1 (All versions < V13.1.0.10), Teamcenter V13.2 (All versions < V13.2.0.9), Teamcenter V13.3 (All versions < V13.3.0.5), Teamcenter V14.0 (All versions < V14.0.0.2). File Server Cache service in Teamcenter is vulnerable to denial of service by entering infinite loops and using up CPU cycles. This could allow an attacker to cause denial of service condition.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Teamcenter | >= 12.4, < 12.4.0.15 |
| Siemens | Teamcenter | >= 13.0, < 13.0.0.10 |
| Siemens | Teamcenter | >= 13.1, < 13.1.0.10 |
| Siemens | Teamcenter | >= 13.2, < 13.2.0.9 |
| Siemens | Teamcenter | >= 13.3, < 13.3.0.5 |
| Siemens | Teamcenter | >= 14.0, < 14.0.0.2 |
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-759952.pdfMitigation, Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-759952.pdfMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-34661?
How severe is CVE-2022-34661?
How do I fix CVE-2022-34661?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-34656Authenticated (admin+) Cross-Site Scripting (XSS) vulnerabil…4.8
- CVE-2022-34657Improper input validation in firmware for some Intel(R) PCSD…4.4
- CVE-2022-34658Multiple Authenticated (contributor+) Persistent Cross-Site …5.4
- CVE-2022-34659A vulnerability has been identified in Simcenter STAR-CCM+ (…5.3
- CVE-2022-3466The version of cri-o as released for Red Hat OpenShift Conta…5.3
- CVE-2022-34660A vulnerability has been identified in Teamcenter V12.4 (All…9.8
- CVE-2022-34662When users add resources to the resource center with a relat…6.5
- CVE-2022-34663A vulnerability has been identified in RUGGEDCOM i800, RUGGE…8
- CVE-2022-34665NVIDIA GPU Display Driver for Windows and Linux contains a v…6.5
- CVE-2022-34666NVIDIA GPU Display Driver for Windows and Linux contains a v…5.5
- CVE-2022-34667NVIDIA CUDA Toolkit SDK contains a stack-based buffer overfl…4.4
- CVE-2022-34668NVFLARE, versions prior to 2.1.4, contains a vulnerability t…9.8
Are you affected by CVE-2022-34661?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
