PT-2022-15684 · Signiant · Signiant Manager+Agents

Anton Golotin

·

Published

2022-03-09

·

Updated

2022-03-15

·

CVE-2022-22795

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Name of the Vulnerable Software and Affected Versions Signiant Manager+Agents (affected versions not specified)
Description The issue allows an attacker to extract internal files of the affected machine through an XML External Entity (XXE) vulnerability. Since the product runs with root privileges on Linux systems and as nt/authority on Windows systems, an attacker can access and extract any file on the system, including sensitive files such as passwd, shadow, and hosts. This access enables the attacker to steal sensitive information from the victim's machine.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-22795

Affected Products

Signiant Manager+Agents