PT-2018-9991 · Sel · Acselerator Architect

Publicado

2018-07-24

·

Atualizado

2019-10-09

·

CVE-2018-10600

CVSS v3.1

9.8

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: SEL AcSELerator Architect versions 2.2.24.0 and prior
Description: The issue allows unsanitized input to be passed to the XML parser, which may lead to disclosure and retrieval of arbitrary data, arbitrary code execution in certain situations on specific platforms, and denial of service attacks.
Recommendations: For SEL AcSELerator Architect versions 2.2.24.0 and prior, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2018-10600

Produtos afetados

Acselerator Architect