PT-2019-10164 · Raritan · Commandcenter Secure Gateway

Faruk Ünal

+1

·

Published

2019-11-18

·

Updated

2019-11-21

·

CVE-2018-20687

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions: Raritan CommandCenter Secure Gateway versions prior to 8.0.0
Description: The issue allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks. This is achieved by sending a crafted DTD in an XML request, exploiting an XML external entity (XXE) vulnerability in the CommandCenterWebServices.
Recommendations: For versions prior to 8.0.0, update to version 8.0.0 or later to resolve the issue. As a temporary workaround, consider restricting access to the CommandCenterWebServices to minimize the risk of exploitation.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2018-20687

Affected Products

Commandcenter Secure Gateway