PT-2013-1309 · Vertiv · Liebert Sitescan

Evgeniy Ermakov

+1

·

Publicado

2013-10-03

·

Atualizado

2017-03-02

·

CVE-2016-8348

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Liebert SiteScan versions prior to 6.5
Description The issue is related to an XML External Entity (XXE) problem, which is caused by incorrect restriction of XML links to external objects. This can allow a remote attacker to gain access to confidential information by using specially crafted XML requests. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser, causing the application to execute arbitrary code or disclose file contents from a server or connected network.
Recommendations For versions prior to 6.5, consider disabling the XML parser or restricting its use until a patch is available to prevent exploitation of the XXE issue. Restrict access to the Liebert SiteScan web interface to minimize the risk of exploitation. Avoid using weakly configured XML parsers in the Liebert SiteScan application until the issue is resolved.

Correção

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2017-02208
CVE-2016-8348

Produtos afetados

Liebert Sitescan