Published:2025/01/14  Last Updated:2025/01/14

JVNVU#98734299
Improper restriction of XML external entity reference (XXE) vulnerability in OMRON NB-Designer

Overview

OMRON NB-Designer contains an improper restriction of XML external entity reference (XXE) vulnerability.

Products Affected

  • NB-Designer Ver.1.63 and earlier
Regarding how to check the affected version, refer to the information provided by the developer.

Description

NB-Designer provided by OMRON Corporation contains an improper restriction of XML external entity reference (XXE) vulnerability (CWE-611, CVE-2024-12298).

Impact

If a user opens a specially crafted project file created by an attacker, sensitive information in the system where NB-Designer is installed may be disclosed.

Solution

Update the software
Update the software to the version listed below which contains a fix for this vulnerability according to the information provided by the developer.

  • NB-Designer Ver.1.64 or later
 Regarding how to obtain a fixed version, refer to the information provided by the developer.

References

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

CVSS v3 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Base Score: 5.5
Attack Vector(AV) Physical (P) Local (L) Adjacent (A) Network (N)
Attack Complexity(AC) High (H) Low (L)
Privileges Required(PR) High (H) Low (L) None (N)
User Interaction(UI) Required (R) None (N)
Scope(S) Unchanged (U) Changed (C)
Confidentiality Impact(C) None (N) Low (L) High (H)
Integrity Impact(I) None (N) Low (L) High (H)
Availability Impact(A) None (N) Low (L) High (H)

Credit

Michael Heinzl reported this vulnerability to JPCERT/CC.
JPCERT/CC coordinated with the developer.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE
JVN iPedia