5.5
CVE-2023-5136
- EPSS 0.25%
- Veröffentlicht 08.11.2023 16:15:11
- Zuletzt bearbeitet 21.11.2024 08:41:08
- Erkennungen
Incorrect Permission Assignment in the TopoGrafix DataPlugin for GPX
An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Ni ≫ Topografix Data Plugin Version 2023 Update - SwPlatform gpx
Ni ≫ Flexlogger Version 2018 Update r1
Ni ≫ Flexlogger Version 2018 Update r2
Ni ≫ Flexlogger Version 2018 Update r3
Ni ≫ Flexlogger Version 2018 Update r4
Ni ≫ Flexlogger Version 2019 Update r1
Ni ≫ Flexlogger Version 2019 Update r2
Ni ≫ Flexlogger Version 2019 Update r3
Ni ≫ Flexlogger Version 2019 Update r4
Ni ≫ Flexlogger Version 2020 Update r1
Ni ≫ Flexlogger Version 2020 Update r2
Ni ≫ Flexlogger Version 2020 Update r3
Ni ≫ Flexlogger Version 2020 Update r4
Ni ≫ Flexlogger Version 2021 Update r1
Ni ≫ Flexlogger Version 2021 Update r2
Ni ≫ Flexlogger Version 2021 Update r3
Ni ≫ Flexlogger Version 2021 Update r4
Ni ≫ Flexlogger Version 2022 Update q2
Ni ≫ Flexlogger Version 2022 Update q4
Ni ≫ Flexlogger Version 2023 Update q1
Ni ≫ Flexlogger Version 2023 Update q2
Ni ≫ Flexlogger Version 2023 Update q3
Ni ≫ Flexlogger Version 2023 Update q4
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.164 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
| security@ni.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.
https://www.ni.com/en/support/documentation/supplemental/23/incorrect-permission-assignment-in-the-topografix-dataplug-for-gpx.html