VYPR

SEVD-2023-129-01

by Schneider Electric

CVEs (2)

  • CVE-2022-46680HigMay 22, 2023
    risk 0.57cvss 8.8epss 0.00

    A CWE-319: Cleartext transmission of sensitive information vulnerability exists that could cause disclosure of sensitive information, denial of service, or modification of data if an attacker is able to intercept network traffic.

  • CVE-2023-2161MedMay 16, 2023
    risk 0.33cvss 5.0epss 0.00

    A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a local user.