Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This may allow an attacker to view sensitive documents and information on the affected host.
References
Link Resource
https://www.cisa.gov/uscert/ics/advisories/icsa-22-228-03 Patch Third Party Advisory US Government Resource
History

No history.

cve-icon MITRE Information

Status: PUBLISHED

Assigner: icscert

Published: 2022-08-16T00:00:00

Updated: 2022-08-31T15:33:04

Reserved: 2022-08-10T00:00:00


Link: CVE-2022-2759

JSON object: View

cve-icon NVD Information

Status : Analyzed

Published: 2022-08-31T16:15:11.450

Modified: 2022-09-02T21:53:44.030


Link: CVE-2022-2759

JSON object: View

cve-icon Redhat Information

No data.

CWE