Vulnerability Details CVE-2021-32972
Panasonic FPWIN Pro, all Versions 7.5.1.1 and prior, allows an attacker to craft a project file specifying a URI that causes the XML parser to access the URI and embed the contents, which may allow the attacker to disclose information that is accessible in the context of the user executing software.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 37.0%
CVSS Severity
CVSS v3 Score 5.5
CVSS v2 Score 4.3
Products affected by CVE-2021-32972
-
cpe:2.3:a:panasonic:fpwin_pro:-
-
cpe:2.3:a:panasonic:fpwin_pro:7.5.0.1
-
cpe:2.3:a:panasonic:fpwin_pro:7.5.1.1