CVE-2018-7837 Vulnerability Details

  /     /     /  

CVE-2018-7837 Metadata Quick Info

CVE Published: 24/12/2018 | CVE Updated: 05/08/2024 | CVE Year: 2018
Source: schneider | Vendor: Schneider Electric SE | Product: IIoT Monitor 3.1.38
Status : PUBLISHED

CVE-2018-7837 Description

An Improper Restriction of XML External Entity Reference (\'XXE\') vulnerability exists on numerous methods of the IIoT Monitor 3.1.38 software that could allow the software to resolve documents outside of the intended sphere of control, causing the software to embed incorrect documents into its output and expose restricted information.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID:
CWE Name: Improper Restriction of XML External Entity Reference ( XXE )
Source: Schneider Electric SE

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).