Vulnerability Description
Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Omron | Cx-Motion Pro | < 1.4.6.014 |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU94200979/Third Party Advisory
- https://jvn.jp/en/vu/JVNVU94200979/Third Party Advisory
FAQ
What is CVE-2023-22322?
CVE-2023-22322 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, ...
How severe is CVE-2023-22322?
CVE-2023-22322 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-22322?
Check the references section above for vendor advisories and patch information. Affected products include: Omron Cx-Motion Pro.