QID 590494
Date Published: 2021-07-29
QID 590494: Panasonic FPWIN Pro XML external entity (XXE) injection Vulnerability(ICSA-21-180-03)
AFFECTED PRODUCTS
Panasonic reports this vulnerability affects the following products:
FPWIN Pro programming control software: All Versions 7.5.1.1 and prior
QID Detection Logic (Authenticated)
QID checks for the Vulnerable version using windows registry keys
Successful exploitation of this vulnerability could allow a remote attacker to retrieve sensitive information from the file system where affected software is installed.
Solution
Customers are advised to refer to CERT MITIGATIONS section ICSA-21-180-03 for affected packages and patching details.
Vendor References
- ICSA-21-180-03 -
www.us-cert.gov/ics/advisories/ICSA-21-180-03
CVEs related to QID 590494
Software Advisories
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-21-180-03 |
|