Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-35904


An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an IFC file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of IFC files could enable an attacker to read information in the context of the current process.


Published

2022-07-15T23:15:08.533

Last Modified

2024-11-21T07:11:55.397

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 3.3 (LOW)

Weaknesses
  • Type: Primary
    CWE-125

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application bentley microstation < 10.17.0 Yes
Application bentley view < 10.17.0 Yes

References