Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-21517

Опубликовано: 01 мар. 2021
Источник: nvd
CVSS3: 7.2
CVSS2: 6.4
EPSS Низкий

Описание

SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:dell:emc_srs_policy_manager:6.6:*:*:*:*:*:*:*
cpe:2.3:a:dell:emc_srs_policy_manager:6.8.3:*:*:*:*:*:*:*
cpe:2.3:a:dell:emc_srs_policy_manager:6.9.0:*:*:*:*:*:*:*

EPSS

Процентиль: 63%
0.00441
Низкий

7.2 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-611
CWE-611

Связанные уязвимости

github
больше 3 лет назад

SRS Policy Manager 6.X is affected by an XML External Entity Injection (XXE) vulnerability due to a misconfigured XML parser that processes user-supplied DTD input without sufficient validation. A remote unauthenticated attacker can potentially exploit this vulnerability to read system files as a non-root user and may be able to temporarily disrupt the ESRS service.

EPSS

Процентиль: 63%
0.00441
Низкий

7.2 High

CVSS3

6.4 Medium

CVSS2

Дефекты

CWE-611
CWE-611