A vulnerability has been identified in Siemens OPC UA Modelling Editor (SiOME) (All versions < V2.8). Affected products suffer from a XML external entity (XXE) injection vulnerability. This vulnerability could allow an attacker to interfere with an application's processing of XML data and read arbitrary files in the system.
CVSS
No CVSS.
References
Link | Resource |
---|---|
https://cert-portal.siemens.com/productcert/pdf/ssa-197270.pdf | Patch Vendor Advisory |
Configurations
History
20 Nov 2023, 15:18
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:siemens:siemens_opc_ua_modeling_editor:*:*:*:*:*:*:*:* | |
References | () https://cert-portal.siemens.com/productcert/pdf/ssa-197270.pdf - Patch, Vendor Advisory | |
First Time |
Siemens siemens Opc Ua Modeling Editor
Siemens |
14 Nov 2023, 11:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2023-11-14 11:15
Updated : 2023-11-20 15:18
NVD link : CVE-2023-46590
Mitre link : CVE-2023-46590
JSON object : View
Products Affected
siemens
- siemens_opc_ua_modeling_editor
CWE
No CWE.