PT-2019-15289 · Advantech · Advantech Wise-Paas/Rmm
Trendytofu
·
Publicado
2019-10-31
·
Atualizado
2021-05-13
·
CVE-2019-18227
CVSS v3.1
7.5
Alta
| Vetor | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Advantech WISE-PaaS/RMM versions 3.3.29 and prior
Description
The issue concerns XML External Entity (XXE) vulnerabilities that may allow the disclosure of sensitive data. Multiple components within Advantech WISE-PaaS/RMM are affected, including WechatSignin, RecoveryMgmt, and AccountMgmt, where various XML External Entity Processing Information Disclosure Vulnerabilities exist. These vulnerabilities can be exploited through different endpoints and parameters, potentially leading to the disclosure of sensitive information.
Recommendations
For Advantech WISE-PaaS/RMM versions 3.3.29 and prior, update to a version later than 3.3.29 to resolve the issue.
As a temporary workaround, consider restricting access to the affected components, such as WechatSignin, RecoveryMgmt, and AccountMgmt, until a patch is available.
Avoid using the vulnerable XML External Entity processing functionality in the affected components until the issue is resolved.
Correção
XXE
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Advantech Wise-Paas/Rmm