CVE Database
/

CVE-2018-17889

Back to search

CVE-2018-17889

Published: Oct 8, 2018

Modified: Sep 17, 2024

PUBLISHED

Description

In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity injection attack, which may allow sensitive information disclosure.

VendorProductVersions

WECON

PI Studio HMI

affected
4.1.9 and prior

WECON

PI Studio

affected
4.2.34 and prior

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now