Medium severity5.0NVD Advisory· Published May 16, 2023· Updated Jun 17, 2026
CVE-2023-2161
CVE-2023-2161
Description
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a local user.
Affected products
4cpe:2.3:a:schneider-electric:opc_factory_server:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:schneider-electric:opc_factory_server:*:*:*:*:*:*:*:*range: <3.63
- cpe:2.3:a:schneider-electric:opc_factory_server:3.63:-:*:*:*:*:*:*
- (no CPE)range: Versions prior to V3.63SP2
Patches
Vulnerability mechanics
References
1- download.schneider-electric.com/filesnvdVendor Advisory
News mentions
0No linked articles in our index yet.