#VU76733 XML injection in UaGateway - CVE-2023-32173
Published: June 1, 2023
UaGateway
Unified Automation GmbH
Description
The vulnerability allows a remote user to perform a denial of service (DoS) attack.
The vulnerability exists due to improper input validation when processing XML data within the implementation of the AddServer method. A remote administrator can pass specially crafted XML data to the application and cause a denial of service condition on the system.