PT-2022-18509 · Delta Electronics · Delta Robot Automation Studio
Kimiya
·
Published
2022-08-31
·
Updated
2022-09-02
·
CVE-2022-2759
CVSS v3.1
8.6
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20
Description
The issue arises from improper restrictions in processing XML documents, allowing XML entities with URIs to resolve to documents outside the intended control sphere. This can cause the product to embed incorrect documents into its output, potentially enabling an attacker to view sensitive documents and information on the affected host.
Recommendations
For versions prior to 1.13.20, update to version 1.13.20 or later to resolve the issue. As a temporary workaround, consider restricting access to XML documents that may contain external entities to minimize the risk of exploitation.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Delta Robot Automation Studio