7.8
CVSSv3

CVE-2021-45845

Published: 25/01/2022 Updated: 27/10/2022
CVSS v2 Base Score: 6.8 | Impact Score: 6.4 | Exploitability Score: 8.6
CVSS v3 Base Score: 7.8 | Impact Score: 5.9 | Exploitability Score: 1.8
VMScore: 605
Vector: AV:N/AC:M/Au:N/C:P/I:P/A:P

Vulnerability Summary

The Path Sanity Check script of FreeCAD 0.19 is vulnerable to OS command injection, allowing an malicious user to execute arbitrary commands via a crafted FCStd document.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

freecadweb freecad 0.19

debian debian linux 11.0

Vendor Advisories

Two vulnerabilities were discovered in FreeCAD, a CAD/CAM program, which could result in the execution of arbitrary shell commands when opening a malformed file For the stable distribution (bullseye), these problems have been fixed in version 0191+dfsg1-2+deb11u1 We recommend that you upgrade your freecad packages For the detailed security sta ...