Siemens patched CADRA for multiple zlib and Foxit flaws; further fixes are still coming for some affected versions. This is CAD software for engineering/manufacturing shops — update now if you run it, and follow Siemens' interim mitigations where a fix isn't out yet.Cyber Resilience desk
What this means for you — CISO:Siemens CADRA inherits multiple zlib and Foxit vulnerabilities. Update to the latest version now; where a fix isn't yet available, apply Siemens' specific countermeasures from the advisory.
What this means for you — Lean IT orgs:This is specialized industrial engineering/documentation software, not general office software — most lean-IT shops don't run it. If you're in manufacturing or plant engineering and do use it, update to the latest version.
What this means for you — MSP:Check client asset lists for Siemens CADRA, especially manufacturing and industrial clients. Update to the latest version where fixes exist, and apply Siemens' interim mitigations for versions still waiting on a patch.
What this means for you — Researcher:Another case of vulnerable third-party components (zlib, Foxit) surfacing in vendor products — worth tracking which CADRA versions map to which bundled library versions as Siemens rolls out further fixes.