PT-2023-7002 · Siemens · Siemens Opc Ua Modeling Editor

Publicado

2023-11-14

·

Atualizado

2023-11-20

·

CVE-2023-46590

CVSS v2.0

7.8

Alta

VetorAV:N/AC:L/Au:N/C:C/I:N/A:N
Name of the Vulnerable Software and Affected Versions Siemens OPC UA Modeling Editor (SiOME) versions prior to V2.8
Description The issue is related to the incorrect restriction of XML links to external objects, which could allow a remote attacker to gain unauthorized access to protected information. This is a XML external entity (XXE) injection vulnerability, which could interfere with an application's processing of XML data and allow the reading of arbitrary files in the system.
Recommendations For versions prior to V2.8, update to version V2.8 or later to resolve the issue. As a temporary workaround, consider restricting the use of XML external entities in the Siemens OPC UA Modeling Editor until a patch is available.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08021
CVE-2023-46590

Produtos afetados

Siemens Opc Ua Modeling Editor