Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-cj8x-q3v5-mmvx

Опубликовано: 14 нояб. 2023
Источник: github
Github: Не прошло ревью
CVSS3: 7.5

Описание

A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products suffer from a XML external entity (XXE) injection vulnerability. This vulnerability could allow an attacker to interfere with an application's processing of XML data and read arbitrary files in the system.

A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products suffer from a XML external entity (XXE) injection vulnerability. This vulnerability could allow an attacker to interfere with an application's processing of XML data and read arbitrary files in the system.

EPSS

Процентиль: 23%
0.00078
Низкий

7.5 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 7.5
nvd
около 2 лет назад

A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products suffer from a XML external entity (XXE) injection vulnerability. This vulnerability could allow an attacker to interfere with an application's processing of XML data and read arbitrary files in the system.

CVSS3: 7.5
fstec
около 2 лет назад

Уязвимость редактора моделирования Siemens OPC UA Modeling Editor (SiOME), связанная с неверным ограничением XML-ссылок на внешние объекты, позволяющая нарушителю получить несанкционированный доступ к защищаемой информации

EPSS

Процентиль: 23%
0.00078
Низкий

7.5 High

CVSS3

Дефекты

CWE-611