Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21266

Опубликовано: 01 фев. 2021
Источник: nvd
CVSS3: 6.4
CVSS3: 5
CVSS2: 4
EPSS Низкий

Описание

openHAB is a vendor and technology agnostic open source automation software for your home. In openHAB before versions 2.5.12 and 3.0.1 the XML external entity (XXE) attack allows attackers in the same network as the openHAB instance to retrieve internal information like the content of files from the file system. Responses to SSDP requests can be especially malicious. All add-ons that use SAX or JAXB parsing of externally received XML are potentially subject to this kind of attack. In openHAB, the following add-ons are potentially impacted: AvmFritz, BoseSoundtouch, DenonMarantz, DLinkSmarthome, Enigma2, FmiWeather, FSInternetRadio, Gce, Homematic, HPPrinter, IHC, Insteon, Onkyo, Roku, SamsungTV, Sonos, Roku, Tellstick, TR064, UPnPControl, Vitotronic, Wemo, YamahaReceiver and XPath Tranformation. The vulnerabilities have been fixed in versions 2.5.12 and 3.0.1 by a more strict configuration of the used XML parser.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:openhab:openhab:*:*:*:*:*:*:*:*
Версия до 2.5.12 (исключая)
cpe:2.3:a:openhab:openhab:3.0.0:*:*:*:*:*:*:*

EPSS

Процентиль: 58%
0.00361
Низкий

6.4 Medium

CVSS3

5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-611

EPSS

Процентиль: 58%
0.00361
Низкий

6.4 Medium

CVSS3

5 Medium

CVSS3

4 Medium

CVSS2

Дефекты

CWE-611