Siemens CADRA Vulnerabilities: Multiple zlib and Foxit Flaws
Siemens CADRA is affected by multiple vulnerabilities in zlib and Foxit, including improper input validation, incorrect bitwise shift of integer, out-of-bounds write, and buffer copy without checking size of input. Siemens recommends updating to the latest version and pro…
Intelligence analysis by Llama
Siemens CADRA has been affected by multiple vulnerabilities in zlib and Foxit, which can lead to denial of service, crashes, and other security issues. Siemens has released a new version and recommends updating to the latest version.
Siemens CADRA has some security issues that need to be fixed. These issues can cause problems like crashes and denial of service. Siemens has released a new version of CADRA that fixes these issues, and it's recommended to update to the latest version to stay safe.
Analysis
Background
Siemens CADRA has been affected by multiple vulnerabilities in zlib and Foxit. These vulnerabilities can lead to denial of service, crashes, and other security issues. Siemens has released a new version and recommends updating to the latest version.
Affected Products
The following versions of Siemens CADRA are affected:
- CADRA vers:intdot/<2511
- vers:all/*
Vulnerabilities
The vulnerabilities in Siemens CADRA include:
- CVE-2005-2096: zlib 1.2 and later versions allows remote attackers to cause a denial of service (crash) via a crafted compressed stream with an incomplete code description of a length greater than 1, which leads to a buffer overflow, as demonstrated using a crafted PNG file.
- CVE-2016-9840: inftrees.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
- CVE-2016-9841: inffast.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact by leveraging improper pointer arithmetic.
- CVE-2016-9842: The inflateMark function in inflate.c in zlib 1.2.8 might allow context-dependent attackers to have unspecified impact via vectors involving left shifts of negative integers.
- CVE-2017-14919: Node.js before 4.8.5, 6.x before 6.11.5, and 8.x before 8.8.0 allows remote attackers to cause a denial of service (uncaught exception and crash) by leveraging a change in the zlib module 1.2.9 making 8 an invalid value for the windowBits parameter.
- CVE-2018-25032: zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
- CVE-2022-37434: zlib through 1.2.12 has a heap-based buffer over-read or buffer overflow in inflate in inflate.c via a large gzip header extra field.
- CVE-2023-45853: MiniZip in zlib through 1.3 has an integer overflow and resultant heap-based buffer overflow in zipOpenNewFileInZip4_64 via a long filename, comment, or extra field.
Remediations
Siemens recommends updating to the latest version of CADRA to prevent potential security issues. Additionally, Siemens provides countermeasures for products where fixes are not available.
Key points
- Siemens CADRA has been affected by multiple vulnerabilities in zlib and Foxit.
- The vulnerabilities can lead to denial of service, crashes, and other security issues.
- Siemens has released a new version and recommends updating to the latest version.
- The affected products include CADRA vers:intdot/<2511 and vers:all/*.
- The vulnerabilities include CVE-2005-2096, CVE-2016-9840, CVE-2016-9841, CVE-2016-9842, CVE-2017-14919, CVE-2018-25032, CVE-2022-37434, and CVE-2023-45853.
If Siemens CADRA is updated to the latest version, the security issues can be resolved, and the system can be protected from potential crashes and denial of service.
If the vulnerabilities in Siemens CADRA are not addressed, it can lead to significant security issues, including denial of service and crashes, which can have severe consequences for critical infrastructure sectors.



