Show plain JSON{"dataType": "CVE_RECORD", "containers": {"adp": [{"title": "CVE Program Container", "references": [{"url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-293-01", "tags": ["government-resource", "x_transferred"]}, {"url": "https://www.bentley.com/advisories/be-2023-0003/", "tags": ["x_transferred"]}], "providerMetadata": {"orgId": "af854a3a-2127-422b-91ae-364da2661108", "shortName": "CVE", "dateUpdated": "2024-08-03T12:14:39.671Z"}}, {"metrics": [{"other": {"type": "ssvc", "content": {"id": "CVE-2022-40201", "role": "CISA Coordinator", "options": [{"Exploitation": "none"}, {"Automatable": "no"}, {"Technical Impact": "total"}], "version": "2.0.3", "timestamp": "2024-05-08T14:45:11.115441Z"}}}], "affected": [{"cpes": ["cpe:2.3:a:bentley:microstation_connect:-:*:*:*:*:*:*:*"], "vendor": "bentley", "product": "microstation_connect", "versions": [{"status": "affected", "version": "-", "versionType": "custom", "lessThanOrEqual": " 10.17.0.209"}], "defaultStatus": "unknown"}], "providerMetadata": {"orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0", "shortName": "CISA-ADP", "dateUpdated": "2024-05-08T14:46:12.264Z"}, "title": "CISA ADP Vulnrichment"}], "cna": {"source": {"discovery": "UNKNOWN"}, "credits": [{"lang": "en", "type": "finder", "user": "00000000-0000-4000-9000-000000000000", "value": "Michael Heinzl"}], "metrics": [{"format": "CVSS", "cvssV3_1": {"scope": "UNCHANGED", "version": "3.1", "baseScore": 7.8, "attackVector": "LOCAL", "baseSeverity": "HIGH", "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H", "integrityImpact": "HIGH", "userInteraction": "REQUIRED", "attackComplexity": "LOW", "availabilityImpact": "HIGH", "privilegesRequired": "NONE", "confidentialityImpact": "HIGH"}, "scenarios": [{"lang": "en", "value": "GENERAL"}]}], "affected": [{"vendor": "Bentley Systems", "product": "MicroStation Connect", "versions": [{"status": "affected", "version": "0", "versionType": "custom", "lessThanOrEqual": "10.17.0.209"}], "defaultStatus": "unaffected"}], "solutions": [{"lang": "en", "value": "Bentley Systems has implemented multiple validation checks within the DGN platform when processing malformed DGNs. Bentley Systems recommends users update to the latest version of the MicroStation Connect:\n\n * MicroStation Connect Update 17.1\n\n\nFor more information and MicroStation updates, contact Bentley Support https://www.bentley.com/support/ .", "supportingMedia": [{"type": "text/html", "value": "<p>Bentley Systems has implemented multiple validation checks within the DGN platform when processing malformed DGNs. Bentley Systems recommends users update to the latest version of the MicroStation Connect:</p><ul><li>MicroStation Connect Update 17.1</li></ul><p>For more information and MicroStation updates, contact <a target=\"_blank\" rel=\"nofollow\" href=\"https://www.bentley.com/support/\">Bentley Support</a>.</p>\n\n<br>", "base64": false}]}], "references": [{"url": "https://www.cisa.gov/uscert/ics/advisories/icsa-22-293-01", "tags": ["government-resource"]}, {"url": "https://www.bentley.com/advisories/be-2023-0003/"}], "x_generator": {"engine": "Vulnogram 0.1.0-dev"}, "descriptions": [{"lang": "en", "value": "Bentley Systems MicroStation Connect\u00a0versions \n\n10.17.0.209 and prior are vulnerable to a Stack-Based Buffer Overflow when a\u00a0malformed design (DGN) file is parsed. This may allow an attacker to execute arbitrary code.", "supportingMedia": [{"type": "text/html", "value": "<span style=\"background-color: rgb(255, 255, 255);\">Bentley Systems MicroStation Connect</span> versions \n\n10.17.0.209 and prior are vulnerable to a Stack-Based Buffer Overflow when a <span style=\"background-color: rgb(255, 255, 255);\">malformed design (DGN) file is parsed. This may allow an attacker to execute arbitrary code.</span>", "base64": false}]}], "problemTypes": [{"descriptions": [{"lang": "en", "type": "CWE", "cweId": "CWE-121", "description": "CWE-121 Stack-Based Buffer Overflow"}]}], "providerMetadata": {"orgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "shortName": "icscert", "dateUpdated": "2024-02-02T05:12:23.789Z"}}}, "cveMetadata": {"cveId": "CVE-2022-40201", "state": "PUBLISHED", "dateUpdated": "2025-02-13T16:33:01.388Z", "dateReserved": "2022-09-29T14:08:03.156Z", "assignerOrgId": "7d14cffa-0d7d-4270-9dc0-52cabd5a23a6", "datePublished": "2023-01-06T21:10:43.968Z", "assignerShortName": "icscert"}, "dataVersion": "5.1"}