CVE Published: 28/03/2022 |
CVE Updated: 02/08/2024 |
CVE Year: 2022 Source: schneider |
Vendor: Schneider Electric |
Product: SCADAPack Workbench Status : PUBLISHED
CVE-2022-0221 Description
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a remote system controlled by an attacker. Affected Product: SCADAPack Workbench (6.6.8a and prior)
Metrics
CVSS Version: 3.1 |
Base Score: 5.5 MEDIUM Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N