CVE-2018-17889
Last modified
CVE-2018-17889 is a vulnerability of currently unknown severity. In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity injection attack, which may allow sensitive information disclosure.. EPSS estimates a 1.25% chance of exploitation in the next 30 days.
Description
In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity injection attack, which may allow sensitive information disclosure.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| We-Con | Pi Studio | <= 4.2.34 |
| We-Con | Pi Studio Hmi | <= 4.1.9 |
References
- https://ics-cert.us-cert.gov/advisories/ICSA-18-277-01Third Party Advisory, US Government Resource
- https://ics-cert.us-cert.gov/advisories/ICSA-18-277-01Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2018-17889?
How severe is CVE-2018-17889?
How do I fix CVE-2018-17889?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2018
- CVE-2018-17881On D-Link DIR-823G 2018-09-19 devices, the GoAhead configura…
- CVE-2018-17882An Integer overflow vulnerability exists in the batchTransfe…
- CVE-2018-17883An issue was discovered in Open Ticket Request System (OTRS)…6.1
- CVE-2018-17884XSS exists in admin/gb-dashboard-widget.php in the Gwolle Gu…
- CVE-2018-17886An issue was discovered in JEESNS 1.3. The XSS filter in com…
- CVE-2018-17888NUUO CMS all versions 3.1 and prior, The application uses a …
- CVE-2018-1789IBM API Connect v2018.1.0 through v2018.3.4 could allow an a…8.4
- CVE-2018-17890NUUO CMS all versions 3.1 and prior, The application uses in…9.8
- CVE-2018-17891Carestream Vue RIS, RIS Client Builds: Version 11.2 and prio…
- CVE-2018-17892NUUO CMS all versions 3.1 and prior, The application impleme…
- CVE-2018-17893LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted …
- CVE-2018-17894NUUO CMS all versions 3.1 and prior, The application creates…
Are you affected by CVE-2018-17889?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
