7.5
CVE-2019-13608
- EPSS 29.4%
- Veröffentlicht 29.08.2019 19:15:13
- Zuletzt bearbeitet 14.03.2025 20:39:08
- Quelle cve@mitre.org
- Teams Watchlist Login
- Unerledigt Login
Citrix StoreFront Server before 1903, 7.15 LTSR before CU4 (3.12.4000), and 7.6 LTSR before CU8 (3.0.8000) allows XXE attacks.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Citrix ≫ Storefront Server Version < 1903
Citrix ≫ Storefront Server Version < 3.12.4000
Citrix ≫ Storefront Server Version < 3.0.8000
03.11.2021: CISA Known Exploited Vulnerabilities (KEV) Catalog
Citrix StoreFront Server XML External Entity (XXE) Processing Vulnerability
SchwachstelleCitrix StoreFront Server contains an XML External Entity (XXE) processing vulnerability that may allow an unauthenticated attacker to retrieve potentially sensitive information.
BeschreibungApply updates per vendor instructions.
Erforderliche MaßnahmenTyp | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 29.4% | 0.964 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
nvd@nist.gov | 5 | 10 | 2.9 |
AV:N/AC:L/Au:N/C:P/I:N/A:N
|
134c704f-9b21-4f2e-91b3-4a467353bcc0 | 7.5 | 3.9 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.