← Vulnerability feed

Vulnerability record · CVE-2020-26987 · published 12 January 2021

CVE-2020-26987: Siemens jt2go heap-based buffer overflow vulnerability

Siemens · Jt2go

A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of TGA files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12016, ZDI-CAN-12017)

8.8 CVSS 3.1 High EPSS 4.3% · top 9.2% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 6.8
4.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
2Affected product versions listed by NVD
6References
17 Jun 2026Last modified by NVD

Description

A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack proper validation of user-supplied data when parsing of TGA files. This could lead to a heap-based buffer overflow. An attacker could leverage this vulnerability to execute code in the context of the current process. (ZDI-CAN-12016, ZDI-CAN-12017)

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Affected products

2 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2020-26987 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

8.8CVE-2021-40355Siemens teamcenter visualization insecure direct object reference vulnerabilityA vulnerability has been identified in Teamcenter V12.4 (All versions < V12.4.0.8), Teamcenter V13.0 (All versions < V13.0.0.7), Teamcenter V13.1 (Al…EPSS 0.80%8.8CVE-2020-26988Siemens jt2go out-of-bounds write vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack …EPSS 3.1%8.8CVE-2020-26990Siemens jt2go type confusion vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0.1), Teamcenter Visualization (All versions < V13.1.0.1). Affected applications l…EPSS 3.9%8.8CVE-2020-26991Siemens jt2go null pointer dereference vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0.2), Teamcenter Visualization (All versions < V13.1.0.2). Affected applications l…EPSS 4.0%8.8CVE-2020-26994Siemens jt2go heap-based buffer overflow vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack …EPSS 2.1%8.8CVE-2020-26995Siemens jt2go out-of-bounds write vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack …EPSS 3.5%8.8CVE-2020-26996Siemens jt2go out-of-bounds read vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack …EPSS 3.1%8.8CVE-2020-26980Siemens jt2go type confusion vulnerabilityA vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). Affected applications lack …EPSS 3.0%

Source: NIST National Vulnerability Database (record CVE-2020-26987), CISA KEV, FIRST EPSS (scores of 2026-09-29). This page is refreshed as NVD updates the record.