« Volver al listado

CVE-2023-43624

Estado: ModificadaMedia (5.5)—

CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4) contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Designer is installed may be disclosed.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-43624",
  "cveTags": [],
  "metrics": {
    "ssvcV203": [
      {
        "source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
        "ssvcData": {
          "id": "CVE-2023-43624",
          "role": "CISA Coordinator",
          "options": [
            {
              "exploitation": "none"
            },
            {
              "automatable": "no"
            },
            {
              "technicalImpact": "partial"
            }
          ],
          "version": "2.0.3",
          "timestamp": "2024-09-11T18:14:29.731149Z"
        }
      }
    ],
    "cvssMetricV31": [
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 5.5,
          "attackVector": "LOCAL",
          "baseSeverity": "MEDIUM",
          "vectorString": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "REQUIRED",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 1.8
      }
    ]
  },
  "affected": [
    {
      "source": "vultures@jpcert.or.jp",
      "affectedData": [
        {
          "vendor": "OMRON Corporation",
          "product": "CX-Designer",
          "versions": [
            {
              "status": "affected",
              "version": "Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4)"
            }
          ]
        }
      ]
    }
  ],
  "published": "2023-10-23T05:15:07.877",
  "references": [
    {
      "url": "https://jvn.jp/en/vu/JVNVU98683567/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-011_en.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "vultures@jpcert.or.jp"
    },
    {
      "url": "https://jvn.jp/en/vu/JVNVU98683567/",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    },
    {
      "url": "https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-011_en.pdf",
      "tags": [
        "Vendor Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Primary",
      "source": "nvd@nist.gov",
      "description": [
        {
          "lang": "en",
          "value": "CWE-611"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4)  contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Designer is installed may be disclosed."
    },
    {
      "lang": "es",
      "value": "CX-Designer Ver.3.740 y anteriores (incluido en CX-One CXONE-AL[][]D-V4) contiene una restricción inadecuada de la vulnerabilidad de referencia de entidad externa XML (XXE). Si un usuario abre un archivo de proyecto especialmente manipulado creado por un atacante, se puede revelar información confidencial en el sistema de archivos donde está instalado CX-Designer."
    }
  ],
  "lastModified": "2026-06-17T06:26:05.740",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:omrom:cx-designer:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "04FBE8C5-B31D-4F1E-B161-7A7084C0C592",
              "versionEndIncluding": "3.740"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "vultures@jpcert.or.jp"
}