Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2020-14478

Опубликовано: 24 фев. 2022
Источник: nvd
CVSS3: 7.1
CVSS2: 5.6
EPSS Низкий

Описание

A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:*:*:*:*:*:*:*:*
Версия до 6.11.00 (включая)

EPSS

Процентиль: 26%
0.00093
Низкий

7.1 High

CVSS3

5.6 Medium

CVSS2

Дефекты

CWE-611
CWE-611

Связанные уязвимости

CVSS3: 7.1
github
почти 4 года назад

A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.

EPSS

Процентиль: 26%
0.00093
Низкий

7.1 High

CVSS3

5.6 Medium

CVSS2

Дефекты

CWE-611
CWE-611