XXE attack in Energy Management Suite - CVE-2018-15444

 

XXE attack in Energy Management Suite - CVE-2018-15444

Published: November 8, 2018


Vulnerability identifier: #VU15762
CSH Severity: Low
CVSS v4: 5.2 [CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:A/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-15444
CWE-ID: CWE-611
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote authenticated attacker to conduct XXE-attack.

The vulnerability exists in the web-based user interface due to improper handling of XML External Entities (XXEs) when parsing an XML file. A remote attacker can trick the victim into open an XML file that submits malicious input and read and write files within the affected application.


Affected software

Energy Management Suite

How to mitigate CVE-2018-15444

Install updates from vendor's website.


External References

Related Security Bulletins