{"resultsPerPage":1,"startIndex":0,"totalResults":1,"format":"NVD_CVE","version":"2.0","timestamp":"2026-05-04T23:24:45.780","vulnerabilities":[{"cve":{"id":"CVE-2023-43624","sourceIdentifier":"vultures@jpcert.or.jp","published":"2023-10-23T05:15:07.877","lastModified":"2024-11-21T08:24:29.470","vulnStatus":"Modified","cveTags":[],"descriptions":[{"lang":"en","value":"CX-Designer Ver.3.740 and earlier (included in CX-One CXONE-AL[][]D-V4)  contains an improper restriction of XML external entity reference (XXE) vulnerability. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Designer is installed may be disclosed."},{"lang":"es","value":"CX-Designer Ver.3.740 y anteriores (incluido en CX-One CXONE-AL[][]D-V4) contiene una restricción inadecuada de la vulnerabilidad de referencia de entidad externa XML (XXE). Si un usuario abre un archivo de proyecto especialmente manipulado creado por un atacante, se puede revelar información confidencial en el sistema de archivos donde está instalado CX-Designer."}],"metrics":{"cvssMetricV31":[{"source":"nvd@nist.gov","type":"Primary","cvssData":{"version":"3.1","vectorString":"CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N","baseScore":5.5,"baseSeverity":"MEDIUM","attackVector":"LOCAL","attackComplexity":"LOW","privilegesRequired":"NONE","userInteraction":"REQUIRED","scope":"UNCHANGED","confidentialityImpact":"HIGH","integrityImpact":"NONE","availabilityImpact":"NONE"},"exploitabilityScore":1.8,"impactScore":3.6}]},"weaknesses":[{"source":"nvd@nist.gov","type":"Primary","description":[{"lang":"en","value":"CWE-611"}]}],"configurations":[{"nodes":[{"operator":"OR","negate":false,"cpeMatch":[{"vulnerable":true,"criteria":"cpe:2.3:a:omrom:cx-designer:*:*:*:*:*:*:*:*","versionEndIncluding":"3.740","matchCriteriaId":"04FBE8C5-B31D-4F1E-B161-7A7084C0C592"}]}]}],"references":[{"url":"https://jvn.jp/en/vu/JVNVU98683567/","source":"vultures@jpcert.or.jp","tags":["Third Party Advisory"]},{"url":"https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-011_en.pdf","source":"vultures@jpcert.or.jp","tags":["Vendor Advisory"]},{"url":"https://jvn.jp/en/vu/JVNVU98683567/","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Third Party Advisory"]},{"url":"https://www.fa.omron.co.jp/product/security/assets/pdf/en/OMSR-2023-011_en.pdf","source":"af854a3a-2127-422b-91ae-364da2661108","tags":["Vendor Advisory"]}]}}]}