First published: Mon Jan 30 2023(Updated: )
Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
OMRON CX-Motion Pro | <1.4.6.014 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-22322 is an improper restriction of XML external entity reference (XXE) vulnerability that exists in OMRON CX-Motion Pro 1.4.6.013 and earlier.
If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed.
CVE-2023-22322 has a severity rating of 5.5 (Medium).
Update OMRON CX-Motion Pro to version 1.4.6.014 or later to fix the CVE-2023-22322 vulnerability.
You can find more information about CVE-2023-22322 at the following reference: [CVE-2023-22322 Reference](https://jvn.jp/en/vu/JVNVU94200979/)