Medium severity5.5NVD Advisory· Published Apr 13, 2022· Updated Jun 17, 2026
CVE-2022-0221
CVE-2022-0221
Description
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a remote system controlled by an attacker. Affected Product: SCADAPack Workbench (6.6.8a and prior)
Affected products
4- Schneider Electric/SCADAPack Workbenchv5Range: 6.6.8a
- Range: <=6.6.8a
<=6.6.8a+ 1 more
- (no CPE)range: <=6.6.8a
- cpe:2.3:a:schneider-electric:scadapack_workbench:*:*:*:*:*:*:*:*range: <=6.6.8a
Patches
Vulnerability mechanics
References
1- www.se.com/ww/en/download/document/SEVD-2022-087-01/nvdMitigationVendor Advisory
News mentions
0No linked articles in our index yet.