Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%
Get alerts for future matching vulnerabilitiesLog in to subscribe
I. Basic Information for CVE-2022-2759
Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Description
Delta Electronics Delta Robot Automation Studio (DRAS) versions prior to 1.13.20 are affected by improper restrictions where the software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. This may allow an attacker to view sensitive documents and information on the affected host.
Source: NVD (National Vulnerability Database)
CVSS Information
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Source: NVD (National Vulnerability Database)
Vulnerability Type
XML外部实体引用的不恰当限制(XXE)
Source: NVD (National Vulnerability Database)
Vulnerability Title
Delta Electronics Delta Robot Automation Studio 代码问题漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Delta Electronics Delta Robot Automation Studio(DRAS)是中国台湾台达电子(Delta Electronics)公司的工业机器人控制软件。 Delta Electronics Delta Robot Automation Studio (DRAS)存在代码问题漏洞,该漏洞源于该软件处理的 XML 文档可能包含 XML 实体,其 URI 解析为预期控制范围之外的文档,导致产品在其输出中嵌入异常文档,攻击者利用该漏洞可以查看受影响主机上的敏感文档和信息。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)
Affected Products
VendorProductAffected VersionsCPESubscribe
Delta ElectronicsDelta Robot Automation Studio (DRAS) All versions ~ 1.13.20 -
II. Public POCs for CVE-2022-2759
#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC
III. Intelligence Information for CVE-2022-2759
Please Login to view more intelligence information
IV. Related Vulnerabilities
V. Comments for CVE-2022-2759

No comments yet


Leave a comment