Schneider Electric Web Designer XML External Entity Vulnerability Allowing Information Disclosure and Remote Code Execution

Vulnerability

A vulnerability allowing improper restriction of XML external entity references has been identified in the Web Designer configuration tool for certain Modicon communication modules. This vulnerability could lead to information disclosure, impact workstation integrity, and allow remote code execution on the compromised computer when a specifically crafted XML file is imported. The issue affects all versions of the Web Designer tool for the following products: BMXNOR0200H, BMXNOE0110(H), BMENOC0311(C), and BMENOC0321(C).

Impact

Exploitation of this vulnerability could result in an XML external entity attack, causing information disclosure, compromising workstation integrity, and allowing remote code execution on the affected computer.

Remediation

Users are advised to encrypt project files, restrict access to trusted users, use secure communication protocols when exchanging files, verify the integrity of project files using hash checks, and follow general cybersecurity best practices such as isolating control systems from business networks and using secure remote access methods like VPNs.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
4.5
impact
7.5
exploitability
4.6
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.