XML external entity (XXE) vulnerability in the WebHMI server in Yokogawa Electric Corporation FAST/TOOLS before R9.05-SP2 allows local users to cause a denial of service (CPU or network traffic consumption) or read arbitrary files via unspecified vectors.
| Software | From | Fixed in |
|---|---|---|
| yokogawa / fast/tools | r9.03 | r9.03.x |
| yokogawa / fast/tools | r9.05 | r9.05.x |
| yokogawa / fast/tools | r9.04 | r9.04.x |
| yokogawa / fast/tools | r9.02 | r9.02.x |
| yokogawa / fast/tools | r9.01 | r9.01.x |