CVE-2023-30795 is an out-of-bounds read vulnerability affecting multiple Siemens products, including JT Open (all versions < V11.4), JT Utilities (all versions < V13.4), and various Parasolid versions. This flaw allows an attacker to execute arbitrary code within the current process by tricking a user into opening a specially crafted JT file. Rated with a CVSS score of 7.8 (HIGH), it requires user interaction (UI:R) and local access (AV:L) but has high impacts on confidentiality, integrity, and availability (C:H/I:H/A:H). Currently, there is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.4CPE matchmatch criteria | cpe:2.3:a:siemens:jt_open:*:*:*:*:*:*:*:* | ||
< 13.4CPE matchmatch criteria | cpe:2.3:a:siemens:jt_utilities:*:*:*:*:*:*:*:* | ||
>= 34.0, < 34.0.253CPE matchmatch criteria | cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:* | ||
>= 34.1, < 34.1.243CPE matchmatch criteria | cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:* | ||
>= 35.0, < 35.0.177CPE matchmatch criteria | cpe:2.3:a:siemens:parasolid:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.