CVE-2023-5179
Estado: ModificadaAlta (7.8)—
An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat sector in a crafted DGN file leads to an out-of-bounds read. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code execution.
CVSS
- Versión: 3.1
- Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- Puntuación base: 7.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 0.27%
- Percentil entre todas las CVEs puntuadas: 18
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-125
- CWE-125
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-5179",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-5179",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "total"
}
],
"version": "2.0.3",
"timestamp": "2024-09-04T19:41:13.254763Z"
}
}
],
"cvssMetricV31": [
{
"type": "Secondary",
"source": "8a9629cb-c5e7-4d2a-a894-111e8039b7ea",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"cvssData": {
"scope": "UNCHANGED",
"version": "3.1",
"baseScore": 7.8,
"attackVector": "LOCAL",
"baseSeverity": "HIGH",
"vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
"integrityImpact": "HIGH",
"userInteraction": "REQUIRED",
"attackComplexity": "LOW",
"availabilityImpact": "HIGH",
"privilegesRequired": "NONE",
"confidentialityImpact": "HIGH"
},
"impactScore": 5.9,
"exploitabilityScore": 1.8
}
]
},
"affected": [
{
"source": "8a9629cb-c5e7-4d2a-a894-111e8039b7ea",
"affectedData": [
{
"vendor": "Open Design Alliance",
"product": "ODA Drawings SDK - All Versions < 2024.10",
"versions": [
{
"status": "affected",
"version": "0",
"lessThan": "2024.10",
"versionType": "custom"
}
],
"defaultStatus": "unaffected"
}
]
}
],
"published": "2023-11-07T16:15:29.550",
"references": [
{
"url": "https://www.opendesign.com/security-advisories",
"tags": [
"Vendor Advisory"
],
"source": "8a9629cb-c5e7-4d2a-a894-111e8039b7ea"
},
{
"url": "https://www.opendesign.com/security-advisories",
"tags": [
"Vendor Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Modified",
"weaknesses": [
{
"type": "Secondary",
"source": "8a9629cb-c5e7-4d2a-a894-111e8039b7ea",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
},
{
"type": "Primary",
"source": "nvd@nist.gov",
"description": [
{
"lang": "en",
"value": "CWE-125"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "An issue was discovered in Open Design Alliance Drawings SDK before 2024.10. A corrupted value for the start of MiniFat sector in a crafted DGN file leads to an out-of-bounds read. This can allow attackers to cause a crash, potentially enabling a denial-of-service attack (Crash, Exit, or Restart) or possible code execution. \n\n\n\n\n"
},
{
"lang": "es",
"value": "Se descubrió un problema en Open Design Alliance Drawings SDK antes de la versión 2024.10. Un valor dañado para el inicio del sector MiniFat en un archivo DGN manipulado genera una lectura fuera de los límites. Esto puede permitir a los atacantes provocar un bloqueo, lo que podría permitir un ataque de Denegación de Servicio (DoS) (bloqueo, salida o reinicio) o una posible ejecución de código."
}
],
"lastModified": "2026-06-17T06:47:44.187",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:opendesign:drawings_sdk:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "163A6555-0C98-45A6-99E1-E7DF7D977DE8",
"versionEndExcluding": "2024.10"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "8a9629cb-c5e7-4d2a-a894-111e8039b7ea"
}