#VU13801 XXE attack in SEL AcSELerator Architect and SEL Compass - CVE-2018-10600
Published: July 11, 2018
SEL AcSELerator Architect
SEL Compass
Schweitzer Engineering Laboratories, Inc.
Description
The vulnerability allows a remote attacker to conduct XXE attack on the target system.
The vulnerability exists due to insufficient validation of user-supplied input. A remote attacker can pass specially crafted input to the AcSELerator Architect XML parser, conduct XXE attack and retrieve arbitrary data or cause the service to crash.