CVE-2023-2161: Schneider Electric Opc Factory Server
Medium severity, CVSS 5.5. EPSS: 0.2% chance of exploitation in the next 30 days.
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause unauthorized read access to the file system when a malicious configuration file is loaded on to the software by a local user.
Affected products
- Schneider Electric Opc Factory Server: before 3.63 (fixed in 3.63); version 3.63 only
Published 2023-05-16. Last modified 2026-06-17.