A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products suffer from a XML external entity (XXE) injection vulnerability. This vulnerability could allow an attacker to interfere with an application's processing of XML data and read arbitrary files in the system.
CVSS
No CVSS.
References
| Link | Resource |
|---|---|
| https://cert-portal.siemens.com/productcert/pdf/ssa-197270.pdf | Patch Vendor Advisory |
Configurations
Information
Published : 2023-11-14 11:15
Updated : 2023-11-20 15:18
NVD link : CVE-2023-46590
Mitre link : CVE-2023-46590
JSON object : View
Products Affected
siemens
- siemens_opc_ua_modeling_editor
CWE
No CWE.
