Bentley Systems develops a tightly focused portfolio of design, visualization, and infrastructure-modeling applications—principally MicroStation, Bentley View, and ContextCapture Viewer—that are widely deployed across engineering and construction workflows and occupy a prominent position in the landscape. The vendor's vulnerability footprint, despite a small product count, spans a large volume of disclosures and concentrates durably around memory-safety issues: out-of-bounds reads and writes, use-after-free conditions, and heap- and stack-based buffer overflows that reflect the native-code complexity and file-parsing demands of computer-aided design and geospatial processing engines. These weakness classes are characteristic of large binaries that parse untrusted CAD, modeling, and image data in complex formats, creating a consistent exposure surface across MicroStation and its variants. Defenders should treat this vendor's updates as broadly applicable to engineering environments and prioritize patching for any internet-connected or data-import-facing deployments; current severity and exploitation figures are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Bentley over time
Signals from CVEs in this vendor scope (224 CVEs).
224 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2021-44228CRITICAL Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect agai | Dec 10, 2021 | 10.0 | 99 | YES | YES |
CVE-2023-4863HIGH Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML pag | Sep 12, 2023 | 8.8 | 96 | YES | NO |
CVE-2021-46604HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.0.80. User interaction is required to exploit t | Feb 18, 2022 | 7.8 | 26 | NO | NO |
CVE-2022-28310HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit | Mar 29, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-28306HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit | Mar 29, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-28305HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit | Mar 29, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-1229HIGH This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit | Mar 28, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-41613HIGH Bentley Systems MicroStation Connect versions
10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when parsing DGN files, which may allow an attacker to crash the | Jan 6, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-40201HIGH Bentley Systems MicroStation Connect versions
10.17.0.209 and prior are vulnerable to a Stack-Based Buffer Overflow when a malformed design (DGN) file is parsed. This may allow a | Jan 6, 2023 | 7.8 | 25 | NO | NO |
CVE-2022-42901HIGH Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds and stack overflow issues when opening crafted XMT files. Exploiting these issues could le | Oct 13, 2022 | 7.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (224 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Bentley.
Media articles that mention a CVE ID that affects a product developed by Bentley — matched by CVE ID, not by vendor name.