PT-2013-1309 · Vertiv · Liebert Sitescan

Evgeniy Ermakov

+1

·

Published

2013-10-03

·

Updated

2017-03-02

·

CVE-2016-8348

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Liebert SiteScan versions prior to 6.5
Description The issue is related to an XML External Entity (XXE) problem, which is caused by incorrect restriction of XML links to external objects. This can allow a remote attacker to gain access to confidential information by using specially crafted XML requests. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser, causing the application to execute arbitrary code or disclose file contents from a server or connected network.
Recommendations For versions prior to 6.5, consider disabling the XML parser or restricting its use until a patch is available to prevent exploitation of the XXE issue. Restrict access to the Liebert SiteScan web interface to minimize the risk of exploitation. Avoid using weakly configured XML parsers in the Liebert SiteScan application until the issue is resolved.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2017-02208
CVE-2016-8348

Affected Products

Liebert Sitescan