← back
CVE-2018-17889

CVE-2018-17889

EPSS 1.2%CWE-611
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS EPSS 1.2%KEV nãoPoC Nuclei Metasploit Patch
Lifecycle
08 Oct 2018Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
In WECON Technology Co., Ltd. PI Studio HMI versions 4.1.9 and prior and PI Studio versions 4.2.34 and prior when parsing project files, the XMLParser that ships with Wecon PIStudio is vulnerable to a XML external entity injection attack, which may allow sensitive information disclosure.

Want to know if your infrastructure is exposed to this?

Talk to TrueHacking →