PT-2022-1741 · Ge · Ge Gas Power Toolboxst
Sharon Briznov
·
Published
2022-01-25
·
Updated
2022-04-04
·
CVE-2021-44477
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
GE Gas Power ToolBoxST version v04.07.05C
Description
The issue is related to an XML external entity (XXE) vulnerability using the DTD parameter entities technique. This could result in the disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project/template file.
Recommendations
For GE Gas Power ToolBoxST version v04.07.05C, ensure that input passed to the XML parser is properly sanitized to prevent exploitation of the XXE vulnerability. As a temporary workaround, consider restricting access to the XML parser or limiting the parsing of XML project/template files until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XXE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ge Gas Power Toolboxst