CVE-2023-46590
CVSS 3.1 Score 7.5 of 10 (high)
Details
Published Nov 14, 2023
Updated: Nov 20, 2023
CWE ID 611
Summary
CVE-2023-46590 is a newly discovered vulnerability affecting Siemens OPC UA Modelling Editor (SiOME) versions prior to V2.8. This issue involves an XML External Entity (XXE) injection, allowing malicious actors to manipulate an application's processing of XML data. Consequently, attackers can potentially read sensitive files on the affected system, posing a significant security risk. It is essential for organizations using SiOME to apply the necessary patches or updates to mitigate this vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Share
Affected Vendors
- Siemens AG