CVE-2023-2161: XEE
Published May 16, 2023
·Updated
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a local user.
Affected Software
2 affected components
Schneider-electric Opc Factory Server<3.63
Schneider-electric Opc Factory Server=3.63
Event History
May 16, 2023
CVE Published
via MITRE·04:31 AM
Data Sourced
via MITRE·04:31 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this vulnerability?
The vulnerability ID of this vulnerability is CVE-2023-2161.
2
What is the severity of CVE-2023-2161?
The severity of CVE-2023-2161 is medium with a CVSS score of 5.5.
3
What is the CWE ID of this vulnerability?
The CWE ID of this vulnerability is CWE-611.
4
Which software is affected by CVE-2023-2161?
The Schneider-electric Opc Factory Server version 3.63 is affected by CVE-2023-2161.
5
How can unauthorized read access to the file system be caused by CVE-2023-2161?
Unauthorized read access to the file system can be caused by loading a malicious configuration file onto the software by a local user.