CVE-2023-32173
Unified Automation UaGateway AddServer XML Injection Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability when the product is in its default configuration.
The specific flaw exists within the implementation of the AddServer method. By specifying crafted arguments, an attacker can cause invalid characters to be inserted into an XML configuration file. An attacker can leverage this vulnerability to create a persistent denial-of-service condition on the system. . Was ZDI-CAN-20576.
CVSS
- Versión: 3.0
- Vector: CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H
- Puntuación base: 5.8
Probabilidad de explotación (EPSS)
- Probabilidad de explotación en los próximos 30 días: 1.17%
- Percentil entre todas las CVEs puntuadas: 66
- Fecha de la puntuación: 6/10/2026
EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).
Tecnologías afectadas (1)
CWE
- CWE-91
Referencias
JSON original (NVD)
Mostrar
{
"id": "CVE-2023-32173",
"cveTags": [],
"metrics": {
"ssvcV203": [
{
"source": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
"ssvcData": {
"id": "CVE-2023-32173",
"role": "CISA Coordinator",
"options": [
{
"exploitation": "none"
},
{
"automatable": "no"
},
{
"technicalImpact": "partial"
}
],
"version": "2.0.3",
"timestamp": "2024-07-09T17:41:33.314153Z"
}
}
],
"cvssMetricV30": [
{
"type": "Secondary",
"source": "zdi-disclosures@trendmicro.com",
"cvssData": {
"scope": "CHANGED",
"version": "3.0",
"baseScore": 5.8,
"attackVector": "NETWORK",
"baseSeverity": "MEDIUM",
"vectorString": "CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:N/I:N/A:H",
"integrityImpact": "NONE",
"userInteraction": "NONE",
"attackComplexity": "HIGH",
"availabilityImpact": "HIGH",
"privilegesRequired": "HIGH",
"confidentialityImpact": "NONE"
},
"impactScore": 4,
"exploitabilityScore": 1.3
}
]
},
"affected": [
{
"source": "zdi-disclosures@trendmicro.com",
"affectedData": [
{
"vendor": "Unified Automation",
"product": "UaGateway",
"versions": [
{
"status": "affected",
"version": "UaGateway 1.5.13"
}
],
"defaultStatus": "unknown"
}
]
}
],
"published": "2024-05-03T02:15:22.940",
"references": [
{
"url": "https://documentation.unified-automation.com/uagateway/1.5.14/CHANGELOG.txt",
"tags": [
"Release Notes"
],
"source": "zdi-disclosures@trendmicro.com"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-23-779/",
"tags": [
"Third Party Advisory"
],
"source": "zdi-disclosures@trendmicro.com"
},
{
"url": "https://documentation.unified-automation.com/uagateway/1.5.14/CHANGELOG.txt",
"tags": [
"Release Notes"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
},
{
"url": "https://www.zerodayinitiative.com/advisories/ZDI-23-779/",
"tags": [
"Third Party Advisory"
],
"source": "af854a3a-2127-422b-91ae-364da2661108"
}
],
"vulnStatus": "Analyzed",
"weaknesses": [
{
"type": "Secondary",
"source": "zdi-disclosures@trendmicro.com",
"description": [
{
"lang": "en",
"value": "CWE-91"
}
]
}
],
"descriptions": [
{
"lang": "en",
"value": "Unified Automation UaGateway AddServer XML Injection Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation UaGateway. Authentication is required to exploit this vulnerability when the product is in its default configuration.\n\nThe specific flaw exists within the implementation of the AddServer method. By specifying crafted arguments, an attacker can cause invalid characters to be inserted into an XML configuration file. An attacker can leverage this vulnerability to create a persistent denial-of-service condition on the system. \n. Was ZDI-CAN-20576."
},
{
"lang": "es",
"value": "Vulnerabilidad de denegación de servicio de inyección XML de Unified Automation UaGateway AddServer. Esta vulnerabilidad permite a atacantes remotos crear una condición de denegación de servicio en las instalaciones afectadas de Unified Automation UaGateway. Se requiere autenticación para aprovechar esta vulnerabilidad cuando el producto está en su configuración predeterminada. La falla específica existe en la implementación del método AddServer. Al especificar argumentos manipulados, un atacante puede provocar que se inserten caracteres no válidos en un archivo de configuración XML. Un atacante puede aprovechar esta vulnerabilidad para crear una condición de denegación de servicio persistente en el sistema. Era ZDI-CAN-20576."
}
],
"lastModified": "2026-06-17T05:58:14.960",
"configurations": [
{
"nodes": [
{
"negate": false,
"cpeMatch": [
{
"criteria": "cpe:2.3:a:unified-automation:uagateway:*:*:*:*:*:*:*:*",
"vulnerable": true,
"matchCriteriaId": "80148EAB-1981-4C32-8580-19D024E5305C",
"versionEndExcluding": "1.5.14.495"
}
],
"operator": "OR"
}
]
}
],
"sourceIdentifier": "zdi-disclosures@trendmicro.com"
}