CVE-2021-41535
moderate-risk
Published 2021-09-28
A vulnerability has been identified in NX 1953 Series (All versions < V1973.3700), NX 1980 Series (All versions < V1988), Solid Edge SE2021 (All versions < SE2021MP8). The affected application contains a use-after-free vulnerability while parsing OBJ files. An attacker could leverage this vulnerability to execute code in the context of the current process (ZDI-CAN-13771).
Do I need to act?
-
0.59% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10
High
LOCAL
/ LOW complexity
Affected Products (15)
Nx 1984 Firmware
Nx 1988 Firmware
Nx 1957 Firmware
Nx 1961 Firmware
Nx 1965 Firmware
Nx 1969 Firmware
Affected Vendors
References (6)
Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-21-1119/
Third Party Advisory
https://www.zerodayinitiative.com/advisories/ZDI-21-1119/
44
/ 100
moderate-risk
Severity
24/34 · High
Exploitability
2/34 · Minimal
Exposure
18/34 · Moderate