PT-2024-17177 · Sew Eurodrive · Sew-Eurodrive Movitools Motionstudio

Esjay

·

Published

2024-02-01

·

Updated

2024-06-06

·

CVE-2024-1167

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions SEW-EURODRIVE MOVITOOLS MotionStudio (affected versions not specified)
Description The issue arises when SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information, leading to unrestricted file access. This can result in information disclosure due to XML External Entity Processing.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-1167
ZDI-24-582

Affected Products

Sew-Eurodrive Movitools Motionstudio