5.4
CVE-2022-43473
- EPSS 19.81%
- Veröffentlicht 30.03.2023 17:15:06
- Zuletzt bearbeitet 21.11.2024 07:26:33
- Erkennungen
A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Zohocorp ≫ Manageengine Opmanager Version < 12.6
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126000
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126001
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126002
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126004
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126005
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126100
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126101
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126102
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126103
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126104
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126107
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126108
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126109
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126110
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126113
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126114
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126115
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126116
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126117
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126118
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126119
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126120
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126121
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126122
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126130
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126131
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126132
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126134
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126135
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126136
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126139
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126141
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126147
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126148
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126149
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126150
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126151
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126154
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126155
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126162
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126163
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126164
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126165
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126166
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126167
Zohocorp ≫ Manageengine Opmanager Version 12.6 Update build126168
Zohocorp ≫ Manageengine Opmanager Plus Version < 12.6
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126001
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126002
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126100
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126103
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126104
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126107
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126113
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126117
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126119
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126122
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126139
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126140
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126141
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126154
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126155
Zohocorp ≫ Manageengine Opmanager Plus Version 12.6 Update build126264
Zohocorp ≫ Manageengine Opmanager Msp Version < 12.6
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126001
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126002
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126100
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126103
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126104
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126107
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126113
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126117
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126119
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126122
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126139
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126140
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126141
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126154
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126155
Zohocorp ≫ Manageengine Opmanager Msp Version 12.6 Update build126264
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 19.81% | 0.971 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| NIST | 5.4 | 2.8 | 2.5 |
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
|
| Cisco Talos | 5.8 | 1.6 | 3.7 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
https://talosintelligence.com/vulnerability_reports/TALOS-2022-1685
https://www.manageengine.com/itom/advisory/cve-2022-43473.html
https://www.talosintelligence.com/vulnerability_reports/TALOS-2022-1685