CVE-2022-47967
Last modified
CVE-2022-47967 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. A vulnerability has been identified in Solid Edge (All versions < V2023 MP1). The DOCMGMT.DLL contains a memory corruption vulnerability that could be triggered while parsing files in different file formats such as PAR, ASM, DFT. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
A vulnerability has been identified in Solid Edge (All versions < V2023 MP1). The DOCMGMT.DLL contains a memory corruption vulnerability that could be triggered while parsing files in different file formats such as PAR, ASM, DFT. This could allow an attacker to execute code in the context of the current process.
Metrics
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Siemens | Solid Edge | < se2023 |
| Siemens | Solid Edge | se2023 |
References
- https://cert-portal.siemens.com/productcert/pdf/ssa-997779.pdfMitigation, Vendor Advisory
- https://cert-portal.siemens.com/productcert/pdf/ssa-997779.pdfMitigation, Vendor Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-47967?
How severe is CVE-2022-47967?
How do I fix CVE-2022-47967?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-47950An issue was discovered in OpenStack Swift before 2.28.1, 2.…6.5
- CVE-2022-47951An issue was discovered in OpenStack Cinder before 19.1.2, 2…5.7
- CVE-2022-47952lxc-user-nic in lxc through 5.0.1 is installed setuid root, …3.3
- CVE-2022-4796Incorrect Use of Privileged APIs in GitHub repository usemem…8.1
- CVE-2022-47965The issue was addressed with improved memory handling. This …7.8
- CVE-2022-47966Multiple Zoho ManageEngine on-premise products, such as Serv…9.8
- CVE-2022-47968Heimdall Application Dashboard through 2.5.4 allows reflecte…5.4
- CVE-2022-4797Improper Restriction of Excessive Authentication Attempts in…4.3
- CVE-2022-47974The Bluetooth AVRCP module has a vulnerability that can lead…6.5
- CVE-2022-47975The DUBAI module has a double free vulnerability. Successful…7.5
- CVE-2022-47976The DMSDP module of the distributed hardware has a vulnerabi…7.5
- CVE-2022-47977A vulnerability has been identified in JT Open (All versions…7.8
Are you affected by CVE-2022-47967?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
