We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2022-2951



Assignericscert
Reserved2022-08-22
Published2022-12-13
Updated2024-08-03

Description

Altair HyperView Player versions 2021.1.0.27 and prior are vulnerable to improper validation of array index vulnerability during processing of H3D files. A DWORD value from a PoC file is extracted and used as an index to write to a buffer, leading to memory corruption.



HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Product status

Default status
unaffected

Any version
affected

Credits

Tran Van Khang of VinCSS working with Trend Micro Zero Day Initiative (ZDI) reported these vulnerabilities to CISA finder

References

https://www.cisa.gov/uscert/ics/advisories/icsa-22-284-01

cve.org CVE-2022-2951

nvd.nist.gov CVE-2022-2951

Download JSON

Share this page
https://cve.threatint.com/CVE/CVE-2022-2951
Support options

Helpdesk Telegram

Subscribe to our newsletter to learn more about our work.