CVE-2021-32972

MEDIUM

Panasonic FPWIN Pro <7.5.1.1 - Info Disclosure

Title source: llm
STIX 2.1

Description

Panasonic FPWIN Pro, all Versions 7.5.1.1 and prior, allows an attacker to craft a project file specifying a URI that causes the XML parser to access the URI and embed the contents, which may allow the attacker to disclose information that is accessible in the context of the user executing software.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-21-180-03

Scores

CVSS v3 5.5
EPSS 0.0069
EPSS Percentile 48.1%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-611
Status published
Products (1)
panasonic/fpwin_pro < 7.5.1.1
Published Jul 09, 2021
Tracked Since Feb 18, 2026