PT-2019-10164 · Raritan · Commandcenter Secure Gateway
Faruk Ünal
+1
·
Published
2019-11-18
·
Updated
2019-11-21
·
CVE-2018-20687
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions:
Raritan CommandCenter Secure Gateway versions prior to 8.0.0
Description:
The issue allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks. This is achieved by sending a crafted DTD in an XML request, exploiting an XML external entity (XXE) vulnerability in the CommandCenterWebServices.
Recommendations:
For versions prior to 8.0.0, update to version 8.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the CommandCenterWebServices to minimize the risk of exploitation.
Fix
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Commandcenter Secure Gateway