Home
MEDIUM: 5.5 CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NDefault status
unaffected
Any version
affected
Description
Delta Electronics EIP Builder version 1.11 is vulnerable to a File Parsing XML External Entity Processing Information Disclosure Vulnerability.
Problem types
CWE-611 XXE - Improper Restriction of XML External Entity Reference
Product status
Any version
Credits
kimiya working with Trend Micro Zero Day Initiative
Derek Vranes of CISA
References
filecenter.deltaww.com/...ation Disclosure Vulnerability.pdf