5.4

CVE-2022-43473

Exploit
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve 
a malicious XML payload to trigger this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Opmanager Version < 12.6
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126000
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126001
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126002
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126004
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126005
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126100
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126101
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126102
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126103
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126104
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126107
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126108
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126109
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126110
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126113
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126114
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126115
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126116
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126117
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126118
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126119
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126120
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126121
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126122
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126130
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126131
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126132
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126134
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126135
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126136
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126139
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126141
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126147
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126148
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126149
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126150
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126151
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126154
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126155
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126162
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126163
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126164
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126165
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126166
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126167
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126168
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126001
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126002
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126100
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126103
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126104
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126107
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126113
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126117
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126119
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126122
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126139
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126140
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126141
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126154
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126155
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126264
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126001
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126002
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126100
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126103
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126104
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126107
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126113
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126117
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126119
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126122
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126139
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126140
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126141
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126154
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126155
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126264
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 19.81% 0.971
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
Cisco Talos 5.8 1.6 3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

https://talosintelligence.com/vulnerability_reports/TALOS-2022-1685
Third Party Advisory
Exploit
https://www.manageengine.com/itom/advisory/cve-2022-43473.html
Patch
Vendor Advisory
https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1685