CVE-2023-37200: XEE
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-37200?
CVE-2023-37200 is a vulnerability that allows an attacker to cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server.
What is the severity of CVE-2023-37200?
CVE-2023-37200 has a severity rating of medium (5.5).
Which software products are affected by CVE-2023-37200?
The Se Ecostruxure Opc Ua Server Expert version 2.01 is affected by CVE-2023-37200.
How can an attacker exploit CVE-2023-37200?
To exploit CVE-2023-37200, an attacker would need to replace a project file on the local filesystem and manually restart the server.
Is there a fix available for CVE-2023-37200?
Yes, a fix is available. Please refer to the security and safety notice provided by Schneider Electric for detailed information on the fix.