First published: Wed Jul 12 2023(Updated: )
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server.
Credit: cybersecurity@se.com cybersecurity@se.com
Affected Software | Affected Version | How to fix |
---|---|---|
Se Ecostruxure Opc Ua Server Expert | <2.01 | |
Se Ecostruxure Opc Ua Server Expert | =2.01 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-37200 is a vulnerability that allows an attacker to cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server.
CVE-2023-37200 has a severity rating of medium (5.5).
The Se Ecostruxure Opc Ua Server Expert version 2.01 is affected by CVE-2023-37200.
To exploit CVE-2023-37200, an attacker would need to replace a project file on the local filesystem and manually restart the server.
Yes, a fix is available. Please refer to the security and safety notice provided by Schneider Electric for detailed information on the fix.