CVE-2016-8348
critical
CVSS v3
9.8
CVSS v2
7.5
VIR risk
9.8
Description
An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.
Predictions
Exploit likelihood
97%
Patch ETA
—
Heuristic predictions, AS-IS, for prioritization only.
Mitigations
Vendor advisory: ics-cert@hq.dhs.gov — https://ics-cert.us-cert.gov/advisories/ICSA-16-334-01
Application impact
| Vendor | Product | Versions | Fixed |
|---|---|---|---|
| emerson | liebert_sitescan_web | {"endIncluding":"6.5"} | |
References
CWEs
CWE-611
Verify integrity in audit chain (admin only). AS-IS.