https://www.us-cert.gov/ics/advisories/icsa-20-154-04INFORMATION EXPOSURE CWE-200
Confidential data is written in an unprotected file, which may allow an attacker to login to the affected node as a low privileged user and read confidential data from an unprotected file.
IMPROPER RESTRICTION OF XML EXTERNAL ENTITY REFERENCE CWE-611
The affected products are vulnerable to an external entity injection, which may allow an attacker to read arbitrary files from the license server and/or from the network. An attacker could also block the license handling.
UNCONTROLLED RESOURCE CONSUMPTION CWE-400
The affected products are vulnerable to a denial-of-service attack, which may allow an attacker to successfully block license handling.
PERMISSIONS, PRIVILEGES, AND ACCESS CONTROLS CWE-264
The affected products are vulnerable to elevation of privileges, which may allow an attacker to alter licenses assigned to system nodes. This could potentially lead to a situation where legitimate nodes in the system network are denied licenses.
IMPROPER ACCESS CONTROL CWE-284
The affected products are vulnerable to weak file permissions, which may allow an attacker to block license handling, escalate privileges, and execute arbitrary code.