ZDI-CAN-21871: ZDI-23-1622: NI DIAdem GPX File Parsing XML External Entity Processing Information Disclosure Vulnerability
This vulnerability allows remote attackers to disclose sensitive information on affected installations of NI DIAdem. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 5.5. The following CVEs are assigned: CVE-2023-5136.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-21871?
ZDI-CAN-21871 has a CVSS rating assigned that indicates its severity level, reflecting the potential impact of the vulnerability.
How do I fix ZDI-CAN-21871?
To mitigate ZDI-CAN-21871, users should apply the latest patches or updates provided by NI for DIAdem.
What type of attacks can ZDI-CAN-21871 be exploited for?
ZDI-CAN-21871 can be exploited by remote attackers to disclose sensitive information from vulnerable installations of NI DIAdem.
Is user interaction required to exploit ZDI-CAN-21871?
Yes, user interaction is required to exploit ZDI-CAN-21871, as the target must visit a malicious page or open a malicious file.
Which software versions are affected by ZDI-CAN-21871?
ZDI-CAN-21871 affects installations of NI DIAdem, but specific vulnerable versions have not been detailed.