Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2017-6323

Опубликовано: 16 апр. 2018
Источник: nvd
CVSS3: 8
CVSS2: 5.2
EPSS Низкий

Описание

The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located, and other system impacts.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:symantec:management_console:*:*:*:*:*:*:*:*
Версия до 8.1 (исключая)
cpe:2.3:a:symantec:management_console:7.6:hf7:*:*:*:*:*:*
cpe:2.3:a:symantec:management_console:8.0:hf6:*:*:*:*:*:*

EPSS

Процентиль: 41%
0.00192
Низкий

8 High

CVSS3

5.2 Medium

CVSS2

Дефекты

CWE-611

Связанные уязвимости

CVSS3: 8
github
больше 3 лет назад

The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located, and other system impacts.

EPSS

Процентиль: 41%
0.00192
Низкий

8 High

CVSS3

5.2 Medium

CVSS2

Дефекты

CWE-611