Improper Restriction of XML External Entities in Schneider Electric Product
CVE-2023-37200

5.5MEDIUM

What is CVE-2023-37200?

An issue has been identified in certain products by Schneider Electric, where improper restrictions related to XML External Entity processing can lead to potential loss of confidentiality. This vulnerability arises when project files are replaced on the local filesystem, followed by a manual server restart, allowing an attacker to exploit the XML parsing capabilities of the application.

Affected Version(s)

EcoStruxure OPC UA Server Expert Versions prior to SV2.01 SP2

References

CVSS V3.1

Score:
5.5
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.