PT-2013-1309 · Vertiv · Liebert Sitescan
Evgeniy Ermakov
+1
·
Publicado
2013-10-03
·
Atualizado
2017-03-02
·
CVE-2016-8348
CVSS v3.1
9.8
Crítica
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Liebert SiteScan versions prior to 6.5
Description
The issue is related to an XML External Entity (XXE) problem, which is caused by incorrect restriction of XML links to external objects. This can allow a remote attacker to gain access to confidential information by using specially crafted XML requests. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser, causing the application to execute arbitrary code or disclose file contents from a server or connected network.
Recommendations
For versions prior to 6.5, consider disabling the XML parser or restricting its use until a patch is available to prevent exploitation of the XXE issue. Restrict access to the Liebert SiteScan web interface to minimize the risk of exploitation. Avoid using weakly configured XML parsers in the Liebert SiteScan application until the issue is resolved.
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Liebert Sitescan