First published: Tue May 16 2023(Updated: )
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a local user.
Credit: cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Schneider-electric Opc Factory Server | <3.63 | |
Schneider-electric Opc Factory Server | =3.63 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this vulnerability is CVE-2023-2161.
The severity of CVE-2023-2161 is medium with a CVSS score of 5.5.
The CWE ID of this vulnerability is CWE-611.
The Schneider-electric Opc Factory Server version 3.63 is affected by CVE-2023-2161.
Unauthorized read access to the file system can be caused by loading a malicious configuration file onto the software by a local user.