Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2022-2759

Опубликовано: 31 авг. 2022
Источник: nvd
CVSS3: 5.5
CVSS3: 8.6
EPSS Низкий

Описание

Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This may allow an attacker to view sensitive documents and information on the affected host.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:deltaww:delta_robot_automation_studio:*:*:*:*:*:*:*:*
Версия до 1.13.20 (исключая)

EPSS

Процентиль: 34%
0.00138
Низкий

5.5 Medium

CVSS3

8.6 High

CVSS3

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8.6
github
больше 3 лет назад

Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This may allow an attacker to view sensitive documents and information on the affected host.

EPSS

Процентиль: 34%
0.00138
Низкий

5.5 Medium

CVSS3

8.6 High

CVSS3

Дефекты

CWE-611