Bentley Bentley

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in any Bentley product.

RSS Feeds for Bentley security vulnerabilities

Create a CVE RSS feed including security vulnerabilities found in Bentley products with stack.watch. Just hit watch, then grab your custom RSS feed url.

Products by Bentley Sorted by Most Security Vulnerabilities since 2018

Bentley Microstation210 vulnerabilities

Bentley View139 vulnerabilities

Bentley Microstation Connect101 vulnerabilities

Bentley View78 vulnerabilities

Bentley Seequent Leapfrog1 vulnerability

Bentley Synchro1 vulnerability

Bentley Synchro 4d1 vulnerability

By the Year

In 2026 there have been 0 vulnerabilities in Bentley. Bentley did not have any published security vulnerabilities last year.




Year Vulnerabilities Average Score
2026 0 0.00
2025 0 0.00
2024 6 5.50
2023 33 7.51
2022 183 6.82
2021 1 10.00

It may take a day or so for new Bentley vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Bentley Security Vulnerabilities

CVE Date Vulnerability Products
CVE-2022-43656 May 07, 2024
Bentley View OOB Read in FBX Parser (CVE202243656) Bentley View FBX File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of FBX files. Crafted data in an FBX file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18492.
View
CVE-2022-43651 May 07, 2024
Bentley View SKP File Parsing Use-After-Free RCE Vulnerability Bentley View SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18960.
View
CVE-2022-43652 May 07, 2024
Bentley View SKP File Parsing Use-After-Free Disclosure Bentley View SKP File Parsing Use-After-Free Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-18981.
View
CVE-2022-43653 May 07, 2024
Bentley View OOB Write in SKP Parsing Enables RCE Bentley View SKP File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. Crafted data in an SKP file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19084.
View
CVE-2022-43655 May 07, 2024
Bentley View FBX Parsing Heap Buffer Overflow RCE Bentley View FBX File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of FBX files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-18491.
View
CVE-2023-44430 May 03, 2024
Bentley View SKP UAF RCE via Malicious File Bentley View SKP File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-19067.
Microstation
View
Bentley View
And others...
CVE-2023-51708 Dec 22, 2023
Bentley eB Sys Mgt Console <=23.00.02.03 Unauth Info Disclosure Bentley eB System Management Console applications within Assetwise Integrity Information Server allow an unauthenticated user to view configuration options via a crafted request, leading to information disclosure. This affects eB System management Console before 23.00.02.03 and Assetwise ALIM For Transportation before 23.00.01.25.
Eb System Management Console
Assetwise Alim Transportation
CVE-2023-4863 Sep 12, 2023
Heap Buffer Overflow in libwebp (Chrome <116.0.5845.187 / libwebp 1.3.2) Heap buffer overflow in libwebp in Google Chrome prior to 116.0.5845.187 and libwebp 1.3.2 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity: Critical)
Seequent Leapfrog
CVE-2022-28313 Mar 29, 2023
Remote Info Leak via 3DS Parse ROP in Bentley MicroStation CONNECT 10.16.02.034 This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DS files. Crafted data in a 3DS file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16343.
Microstation
View
Microstation Connect
And others...
CVE-2022-28314 Mar 29, 2023
BENTLEY MicroStation CONNECT 10.16.02.34: IFC buffer overflow This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16332.
Microstation
View
Microstation Connect
And others...
CVE-2022-28644 Mar 29, 2023
Remote Code Exec in Bentley MicroStation CONNECT 10.16.02.34 via DGN Buffer Overflow This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DGN files. Crafted data in a DGN file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16469.
Microstation
View
Microstation Connect
And others...
CVE-2022-28645 Mar 29, 2023
Bentley MicroStation CONNECT 10.16.02.34 DGN Parse ROP Disclosure & RCE This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DGN files. Crafted data in a DGN file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16470.
Microstation
View
Microstation Connect
And others...
CVE-2022-28646 Mar 29, 2023
Bentley MicroStation CONNECT 10.16.2.034: IFC File Buffer Overrun CVE-2022-28646 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16570.
Microstation
View
Microstation Connect
And others...
CVE-2022-28647 Mar 29, 2023
RCE via IFC File Parser in Bentley MicroStation CONNECT 10.16.2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16573.
Microstation
View
Microstation Connect
And others...
CVE-2022-28303 Mar 29, 2023
Remote Code Exec CVE-2022-28303 in Bentley View 10.16.02.022 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.16.02.022. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16280.
Microstation
View
CVE-2022-28304 Mar 29, 2023
Remote Code Exec in Bentley MicroStation v10.16.02.034 via OBJ Buffer Overflow This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OBJ files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16171.
Microstation
View
Microstation Connect
And others...
CVE-2022-28305 Mar 29, 2023
Remote Code Exec in Bentley MicroStation CONNECT 10 OBJ Parser <10.16.02.034 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OBJ files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16172.
Microstation
View
Microstation Connect
And others...
CVE-2022-28306 Mar 29, 2023
RCE via OBJ parsing in Bentley MicroStation CONNECT 10.16.02.034 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of OBJ files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this to execute code in the context of the current process. Was ZDI-CAN-16174.
Microstation
View
Microstation Connect
And others...
CVE-2022-28307 Mar 29, 2023
Bentley View 10.16.02.022: DXF BufOver Allow RCE via Crafted DXF This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.16.02.022. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. Crafted data in a DXF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16306.
Microstation
View
CVE-2022-28312 Mar 29, 2023
Info Disclosure via Buffer Overread in Bentley MicroStation 10.16.02.034 3DS This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DS files. Crafted data in a 3DS file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16342.
Microstation
View
Microstation Connect
And others...
CVE-2022-28315 Mar 29, 2023
Bentley MicroStation CONNECT 10.16.02.34 IFC Parsing Buffer Overflow This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a fixed-length stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16367.
Microstation
View
Microstation Connect
And others...
CVE-2022-28316 Mar 29, 2023
Bentley MicroStation CONNECT 10.16.02.34 RCE via IFC Buffer Overflow This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16368.
Microstation
View
Microstation Connect
And others...
CVE-2022-28317 Mar 29, 2023
Bentley MicroStation CONNECT 10.16.02.34 RCE via IFC Parser This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16369.
Microstation
View
Microstation Connect
And others...
CVE-2022-28318 Mar 29, 2023
Bentley MicroStation CONNECT 10.16.02.34 IFC Write-After-Buf Exec This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16379.
Microstation
View
Microstation Connect
And others...
CVE-2022-28319 Mar 29, 2023
Bentley MicroStation CONNECT 10.16.02.034 RCE via 3DM file (memory init flaw) This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DM files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16340.
Microstation
View
Microstation Connect
And others...
CVE-2022-28320 Mar 29, 2023
Bentley View 10.16.02.022 3DM Parsing RCE (Arbitrary Code Exec) This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.16.02.022. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DM files. The issue results from the lack of proper initialization of memory prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16282.
Microstation
View
CVE-2022-28641 Mar 29, 2023
Bentley MicroStation CONNECT 10.16.02.34 IFC Parser RCE This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16390.
Microstation
View
Microstation Connect
And others...
CVE-2022-28642 Mar 29, 2023
Remote Code Exec via DGN Buffer Overflow in Bentley MicroStation 10.16.02.34 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DGN files. Crafted data in a DGN file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16424.
Microstation
View
Microstation Connect
And others...
CVE-2022-28643 Mar 29, 2023
RCE CVE-2022-28643 in Bentley MicroStation 10.16.02.34 via DGN overflow This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DGN files. Crafted data in a DGN file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16468.
Microstation
View
Microstation Connect
And others...
CVE-2022-28308 Mar 29, 2023
Bentley View 10.16.02.022 3DS parsing buffer overread info disclosure This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.16.02.022. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DS files. Crafted data in a 3DS file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16307.
Microstation
View
CVE-2022-28309 Mar 29, 2023
Bentley View 10.16.02.022 - 3DS File Parser Buffer Overread This vulnerability allows remote attackers to disclose sensitive information on affected installations of Bentley View 10.16.02.022. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of 3DS files. Crafted data in a 3DS file can trigger a read past the end of an allocated buffer. An attacker can leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process. Was ZDI-CAN-16308.
Microstation
View
Bentley View
And others...
CVE-2022-28310 Mar 29, 2023
RCE via SKP parsing in Bentley MicroStation CONNECT 10.16.02.034 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of SKP files. The issue results from the lack of validating the existence of an object prior to performing operations on the object. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16339.
Microstation
View
Microstation Connect
And others...
CVE-2022-28311 Mar 29, 2023
Remote Code Exec in Bentley MicroStation CONNECT 10.16.02.034 via DXF parse This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DXF files. Crafted data in a DXF file can trigger a read past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16341.
Microstation
View
Microstation Connect
And others...
CVE-2022-28300 Mar 29, 2023
RCE in Bentley MicroStation 10.16.02.034 via JP2 Image Parser This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation 10.16.02.034 CONNECT. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of JP2 images. Crafted data in a JP2 file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16202.
Microstation
View
CVE-2022-28301 Mar 29, 2023
MicroStation CONNECT 10.16.02.34 IFC Buffer Overflow RCE This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16392.
Microstation
View
Microstation Connect
CVE-2022-28302 Mar 29, 2023
MicroStation CONNECT 10.16 IFC Buffer Overread -> Arbitrary Exec This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.02.34. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a read past the end of an allocated buffer. An attacker can leverage this to execute code in the context of the current process. Was ZDI-CAN-16446.
Microstation
View
Microstation Connect
And others...
CVE-2022-1229 Mar 28, 2023
Bentley MicroStation CONNECT 10.16.2.034 IFC buffer overflow RCE This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley MicroStation CONNECT 10.16.2.034. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of IFC files. Crafted data in an IFC file can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-16581.
Microstation Connect
CVE-2022-40201 Jan 06, 2023
MicroStation Connect 10.17.0.209-: Stack Buffer Overflow in DGN Parser Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to a Stack-Based Buffer Overflow when a malformed design (DGN) file is parsed. This may allow an attacker to execute arbitrary code.
Microstation Connect
CVE-2022-41613 Jan 06, 2023
MicroStation Connect OOBR in DGN Parsing (10.17.0.209) Bentley Systems MicroStation Connect versions 10.17.0.209 and prior are vulnerable to an Out-of-Bounds Read when when parsing DGN files, which may allow an attacker to crash the product, disclose sensitive information, or execute arbitrary code.
Microstation Connect
CVE-2022-42899 Oct 13, 2022
Bentley MicroStation OOB Read/Stack Overflow in SKP (Pre-10.17.01.58) Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read and stack overflow issues when opening crafted SKP files. Exploiting these issues could lead to information disclosure and code execution. The fixed versions are 10.17.01.58* for MicroStation and 10.17.01.19* for Bentley View.
Microstation
View
CVE-2022-42901 Oct 13, 2022
Bentley MicroStation OOB & stack overflow via crafted XMT (pre-10.17.01.58) Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds and stack overflow issues when opening crafted XMT files. Exploiting these issues could lead to information disclosure and code execution. The fixed versions are 10.17.01.58* for MicroStation and 10.17.01.19* for Bentley View.
Microstation
View
CVE-2022-42900 Oct 13, 2022
OOB read in FBX parser of Bentley MicroStation (<10.17.01.58 & <10.17.01.19) Bentley MicroStation and MicroStation-based applications may be affected by out-of-bounds read issues when opening crafted FBX files. Exploiting these issues could lead to information disclosure and code execution. The fixed versions are 10.17.01.58* for MicroStation and 10.17.01.19* for Bentley View.
Microstation
View
CVE-2022-35904 Jul 15, 2022
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an IFC file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of IFC files could enable an attacker to read information in the context of the current process.
Microstation
View
CVE-2022-35906 Jul 15, 2022
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a DGN file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of DGN files could enable an attacker to read information in the context of the current process.
Microstation
View
CVE-2022-35905 Jul 15, 2022
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an FBX file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of FBX files could enable an attacker to read information in the context of the current process.
Microstation
View
CVE-2022-35903 Jul 15, 2022
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a 3DS file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of 3DS files could enable an attacker to read information in the context of the current process.
Microstation
View
CVE-2022-35902 Jul 15, 2022
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open an OBJ file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of OBJ files could enable an attacker to read information in the context of the current process.
Microstation
View
CVE-2022-35900 Jul 15, 2022
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a JP2 file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of JP2 files could enable an attacker to read information in the context of the current process.
Microstation
View
CVE-2022-35901 Jul 15, 2022
An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x An issue was discovered in Bentley MicroStation before 10.17.0.x and Bentley View before 10.17.0.x. Using an affected version of MicroStation or MicroStation-based application to open a J2K file containing crafted data can force an out-of-bounds read. Exploitation of these vulnerabilities within the parsing of J2K files could enable an attacker to read information in the context of the current process.
Microstation
View
CVE-2021-46643 Feb 18, 2022
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Bentley View 10.15.0.75. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of DGN files. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-15515.
Microstation
View
Built by Foundeo Inc., with data from the National Vulnerability Database (NVD). Privacy Policy. Use of this site is governed by the Legal Terms
Disclaimer
CONTENT ON THIS WEBSITE IS PROVIDED ON AN "AS IS" BASIS AND DOES NOT IMPLY ANY KIND OF GUARANTEE OR WARRANTY, INCLUDING THE WARRANTIES OF MERCHANTABILITY OR FITNESS FOR A PARTICULAR USE. YOUR USE OF THE INFORMATION ON THE DOCUMENT OR MATERIALS LINKED FROM THE DOCUMENT IS AT YOUR OWN RISK. Always check with your vendor for the most up to date, and accurate information.