#VU66775 XML External Entity injection in AVEVA Edge - CVE-2022-36969
Published: August 26, 2022
AVEVA Edge
AVEVA Software, LLC.
Description
The vulnerability allows a remote attacker to compromise the target system.
The vulnerability exists due to insufficient validation of user-supplied XML input within the LoadImportedLibraries method. A remote attacker can trick a victim to open a specially crafted file and view contents of arbitrary files on the system or perform a denial of service (DoS) attack.