Vulnerabilities > CVE-2021-25175 - Incorrect Type Conversion or Cast vulnerability in multiple products
Attack vector
NETWORK Attack complexity
MEDIUM Privileges required
NONE Confidentiality impact
PARTIAL Integrity impact
PARTIAL Availability impact
PARTIAL Summary
An issue was discovered in Open Design Alliance Drawings SDK before 2021.11. A Type Conversion issue exists when rendering malformed .DXF and .DWG files. This can allow attackers to cause a crash, potentially enabling a denial of service attack (Crash, Exit, or Restart).
Vulnerable Configurations
Common Weakness Enumeration (CWE)
References
- https://www.opendesign.com/security-advisories
- https://cert-portal.siemens.com/productcert/pdf/ssa-663999.pdf
- https://www.zerodayinitiative.com/advisories/ZDI-21-218/
- https://www.zerodayinitiative.com/advisories/ZDI-21-245/
- https://www.zerodayinitiative.com/advisories/ZDI-21-223/
- https://www.zerodayinitiative.com/advisories/ZDI-21-244/
- https://www.zerodayinitiative.com/advisories/ZDI-21-246/
- https://www.zerodayinitiative.com/advisories/ZDI-21-224/
- https://cert-portal.siemens.com/productcert/pdf/ssa-155599.pdf