Vulnerabilities > CVE-2023-22322 - XXE vulnerability in Omron Cx-Motion PRO 1.4.6.013

047910
CVSS 5.5 - MEDIUM
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
NONE
local
low complexity
omron
CWE-611

Summary

Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed.

Vulnerable Configurations

Part Description Count
Application
Omron
2