VYPR

SEVD-2023-192-02

by Schneider Electric

CVEs (2)

  • CVE-2023-29414HigJul 12, 2023
    risk 0.51cvss 7.8epss 0.00

    A CWE-120: Buffer Copy without Checking Size of Input (Classic Buffer Overflow) vulnerability exists that could cause user privilege escalation if a local user sends specific string input to a local function call.

  • CVE-2023-37200MedJul 12, 2023
    risk 0.36cvss 5.5epss 0.00

    A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server.