CVE-2022-41613 HIGH

CVE-2022-41613

Vendor Bentley Systems
Product MicroStation Connect
Weakness CWE-125
Published January 6, 2023
Last update February 13, 2025

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction Required
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when parsing DGN files, which may allow an attacker to crash the product, disclose sensitive information, or execute arbitrary code.

Key dates

02Disclosure timeline

January 6, 2023 CVE published
February 13, 2025 Record updated