5.5
CVE-2023-5136
- EPSS 0.08%
- Published 08.11.2023 16:15:11
- Last modified 21.11.2024 08:41:08
- Source security@ni.com
- Teams watchlist Login
- Open Login
An incorrect permission assignment in the TopoGrafix DataPlugin for GPX could result in information disclosure. An attacker could exploit this vulnerability by getting a user to open a specially crafted data file.
Data is provided by the National Vulnerability Database (NVD)
Ni ≫ Topografix Data Plugin Version2023 Update- SwPlatformgpx
Ni ≫ Flexlogger Version2018 Updater1
Ni ≫ Flexlogger Version2018 Updater2
Ni ≫ Flexlogger Version2018 Updater3
Ni ≫ Flexlogger Version2018 Updater4
Ni ≫ Flexlogger Version2019 Updater1
Ni ≫ Flexlogger Version2019 Updater2
Ni ≫ Flexlogger Version2019 Updater3
Ni ≫ Flexlogger Version2019 Updater4
Ni ≫ Flexlogger Version2020 Updater1
Ni ≫ Flexlogger Version2020 Updater2
Ni ≫ Flexlogger Version2020 Updater3
Ni ≫ Flexlogger Version2020 Updater4
Ni ≫ Flexlogger Version2021 Updater1
Ni ≫ Flexlogger Version2021 Updater2
Ni ≫ Flexlogger Version2021 Updater3
Ni ≫ Flexlogger Version2021 Updater4
Ni ≫ Flexlogger Version2022 Updateq2
Ni ≫ Flexlogger Version2022 Updateq4
Ni ≫ Flexlogger Version2023 Updateq1
Ni ≫ Flexlogger Version2023 Updateq2
Ni ≫ Flexlogger Version2023 Updateq3
Ni ≫ Flexlogger Version2023 Updateq4
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Type | Source | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.08% | 0.256 |
Source | Base Score | Exploit Score | Impact Score | Vector string |
---|---|---|---|---|
nvd@nist.gov | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
security@ni.com | 5.5 | 1.8 | 3.6 |
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CWE-732 Incorrect Permission Assignment for Critical Resource
The product specifies permissions for a security-critical resource in a way that allows that resource to be read or modified by unintended actors.