CVE-2023-5180
Estado: ModificadaAlta (7.8)—
An issue was discovered in Open Design Alliance Drawings SDK before 2024.12. A corrupted value of number of sectors used by the Fat structure in a crafted DGN file leads to an out-of-bounds write. An attacker can leverage this vulnerability to execute code in the context of the current process.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.19%
- Percentil entre todas las CVEs puntuadas: 8
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-787
- CWE-787
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-5180",
"cveTags": [],
"metrics": {
"cvssMetricV31": [
{
"type": "Secondary",
"source": "8a9629cb-c5e7-4d2a-a894-111e8039b7ea",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "8a9629cb-c5e7-4d2a-a894-111e8039b7ea",
"affectedData": [
{
"vendor": "Open Design Alliance",
"product": "ODA Drawings SDK - All Versions < 2024.12",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2024.12",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-12-26T09:15:07.197",
"references": [
{
"url": "https://www.opendesign.com/security-advisories",
"tags": [
"Vendor Advisory"
],
"source": "8a9629cb-c5e7-4d2a-a894-111e8039b7ea"
},
{
"url": "https://www.opendesign.com/security-advisories",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "8a9629cb-c5e7-4d2a-a894-111e8039b7ea",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-787"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in Open Design Alliance\nDrawings SDK before 2024.12. A corrupted value of number\nof sectors used by the Fat structure in a crafted DGN file leads to an\nout-of-bounds write. An attacker can leverage this vulnerability to execute\ncode in the context of the current process."
},
{
"lang": "es",
"value": "Se descubrió un problema en Open Design Alliance Drawings SDK antes del 2024.12. Un valor corrupto del número de sectores utilizados por la estructura Fat en un archivo DGN diseñado provoca una escritura fuera de los límites. Un atacante puede aprovechar esta vulnerabilidad para ejecutar código en el contexto del proceso actual."
}
],
"lastModified": "2026-06-17T06:47:44.313",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:opendesign:drawings_sdk:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "0DFA8267-F3BE-470D-8077-A46EAD298F27",
"versionEndExcluding": "2024.12"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "8a9629cb-c5e7-4d2a-a894-111e8039b7ea"
}