Publication Date: 2021-03-09
Last Update: 2021-04-13
Current Version: V1.1
CVSS v3.1 Base Score: 7.8

Affected Product and Versions Remediation
Solid Edge SE2020:
All Versions < SE2020MP13
Update to SE2020MP13 or later version
https://support.sw.siemens.com/ (login required)
Solid Edge SE2021:
All Versions < SE2021MP3
Update to SE2021MP3 or later version
https://support.sw.siemens.com/ (login required)
Solid Edge SE2021:
SE2021MP3
only affected by CVE-2020-28385, CVE-2021-27380
Update to SE2021MP4 or later version
https://support.sw.siemens.com/ (login required)

CVSS v3.1 Base Score 7.8
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-787: Out-of-bounds Write

CVSS v3.1 Base Score 5.6
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:N/A:L/E:P/RL:O/RC:C
CWE: CWE-611: Improper Restriction of XML External Entity Reference

CVSS v3.1 Base Score 7.8
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-787: Out-of-bounds Write

CVSS v3.1 Base Score 7.8
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H/E:P/RL:O/RC:C
CWE: CWE-125: Out-of-bounds Read

https://www.siemens.com/cert/advisories