6.5
CVE-2022-2330
- EPSS 0.34%
- Veröffentlicht 30.08.2022 08:15:07
- Zuletzt bearbeitet 21.11.2024 07:00:46
- Quelle trellixpsirt@trellix.com
- Teams Watchlist Login
- Unerledigt Login
Improper Restriction of XML External Entity Reference vulnerability in DLP Endpoint for Windows prior to 11.9.100 allows a remote attacker to cause the DLP Agent to access a local service that the attacker wouldn't usually have access to via a carefully constructed XML file, which the DLP Agent doesn't parse correctly.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Mcafee ≫ Data Loss Prevention Endpoint Version < 11.6.600.212
Mcafee ≫ Data Loss Prevention Endpoint Version >= 11.9.0 < 11.9.100
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
Typ | Quelle | Score | Percentile |
---|---|---|---|
EPSS | FIRST.org | 0.34% | 0.565 |
Quelle | Base Score | Exploit Score | Impact Score | Vector String |
---|---|---|---|---|
nvd@nist.gov | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
trellixpsirt@trellix.com | 6.5 | 2.8 | 3.6 |
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.