CVE-2023-2161

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
16/05/2023
Last modified:
25/05/2023

Description

<br /> A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that<br /> could cause unauthorized read access to the file system when a malicious configuration file is<br /> loaded on to the software by a local user. 

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:schneider-electric:opc_factory_server:*:*:*:*:*:*:*:* 3.63 (excluding)
cpe:2.3:a:schneider-electric:opc_factory_server:3.63:-:*:*:*:*:*:*