5.5
CVE-2023-37200
- EPSS 0.04%
- Veröffentlicht 12.07.2023 08:15:10
- Zuletzt bearbeitet 21.11.2024 08:11:10
- Quelle cybersecurity@se.com
- CVE-Watchlists
- Unerledigt
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Se ≫ Ecostruxure Opc Ua Server Expert Version < 2.01
Se ≫ Ecostruxure Opc Ua Server Expert Version2.01 Update-
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.04% | 0.115 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
| cybersecurity@se.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.