Vulnerability Description
CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Designer is installed may be disclosed.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Omrom | Cx-Designer | <= 3.740 |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/vu/JVNVU98683567/Third Party Advisory
- https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-011_en.pdfVendor Advisory
- https://jvn.jp/en/vu/JVNVU98683567/Third Party Advisory
- https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-011_en.pdfVendor Advisory
FAQ
What is CVE-2023-43624?
CVE-2023-43624 is a vulnerability with a CVSS score of 5.5 (MEDIUM). CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted proj...
How severe is CVE-2023-43624?
CVE-2023-43624 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-43624?
Check the references section above for vendor advisories and patch information. Affected products include: Omrom Cx-Designer.