VYPR
Medium severity5.5NVD Advisory· Published Oct 23, 2023· Updated Jun 17, 2026

CVE-2023-43624

CVE-2023-43624

Description

CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Designer is installed may be disclosed.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

3
  • OMRON Corporation/CX-Designerv5
    Range: Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4)
  • Omron/CX-Designerllm-create
    Range: <=3.740
  • cpe:2.3:a:omrom:cx-designer:*:*:*:*:*:*:*:*
    Range: <=3.740

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.