PT-2023-15505 · Netcad · Netcad Keos

Published

2023-01-31

·

Updated

2023-02-08

·

CVE-2022-47873

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Netcad KEOS version 1.0
Description The issue is related to an XML External Entity (XXE) vulnerability, which can result in Server-Side Request Forgery (SSRF) with XXE. This allows for remote exploitation.
Recommendations For Netcad KEOS version 1.0, as a temporary workaround, consider disabling XML External Entity processing until a patch is available. Restrict access to sensitive areas of the application to minimize the risk of exploitation.

Fix

XXE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2022-47873

Affected Products

Netcad Keos