5.8

CVE-2022-43473

Exploit

A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve 
a malicious XML payload to trigger this vulnerability.

Data is provided by the National Vulnerability Database (NVD)
ZohocorpManageengine Opmanager Version < 12.6
ZohocorpManageengine Opmanager Version12.6 Updatebuild126000
ZohocorpManageengine Opmanager Version12.6 Updatebuild126001
ZohocorpManageengine Opmanager Version12.6 Updatebuild126002
ZohocorpManageengine Opmanager Version12.6 Updatebuild126004
ZohocorpManageengine Opmanager Version12.6 Updatebuild126005
ZohocorpManageengine Opmanager Version12.6 Updatebuild126100
ZohocorpManageengine Opmanager Version12.6 Updatebuild126101
ZohocorpManageengine Opmanager Version12.6 Updatebuild126102
ZohocorpManageengine Opmanager Version12.6 Updatebuild126103
ZohocorpManageengine Opmanager Version12.6 Updatebuild126104
ZohocorpManageengine Opmanager Version12.6 Updatebuild126107
ZohocorpManageengine Opmanager Version12.6 Updatebuild126108
ZohocorpManageengine Opmanager Version12.6 Updatebuild126109
ZohocorpManageengine Opmanager Version12.6 Updatebuild126110
ZohocorpManageengine Opmanager Version12.6 Updatebuild126113
ZohocorpManageengine Opmanager Version12.6 Updatebuild126114
ZohocorpManageengine Opmanager Version12.6 Updatebuild126115
ZohocorpManageengine Opmanager Version12.6 Updatebuild126116
ZohocorpManageengine Opmanager Version12.6 Updatebuild126117
ZohocorpManageengine Opmanager Version12.6 Updatebuild126118
ZohocorpManageengine Opmanager Version12.6 Updatebuild126119
ZohocorpManageengine Opmanager Version12.6 Updatebuild126120
ZohocorpManageengine Opmanager Version12.6 Updatebuild126121
ZohocorpManageengine Opmanager Version12.6 Updatebuild126122
ZohocorpManageengine Opmanager Version12.6 Updatebuild126130
ZohocorpManageengine Opmanager Version12.6 Updatebuild126131
ZohocorpManageengine Opmanager Version12.6 Updatebuild126132
ZohocorpManageengine Opmanager Version12.6 Updatebuild126134
ZohocorpManageengine Opmanager Version12.6 Updatebuild126135
ZohocorpManageengine Opmanager Version12.6 Updatebuild126136
ZohocorpManageengine Opmanager Version12.6 Updatebuild126139
ZohocorpManageengine Opmanager Version12.6 Updatebuild126141
ZohocorpManageengine Opmanager Version12.6 Updatebuild126147
ZohocorpManageengine Opmanager Version12.6 Updatebuild126148
ZohocorpManageengine Opmanager Version12.6 Updatebuild126149
ZohocorpManageengine Opmanager Version12.6 Updatebuild126150
ZohocorpManageengine Opmanager Version12.6 Updatebuild126151
ZohocorpManageengine Opmanager Version12.6 Updatebuild126154
ZohocorpManageengine Opmanager Version12.6 Updatebuild126155
ZohocorpManageengine Opmanager Version12.6 Updatebuild126162
ZohocorpManageengine Opmanager Version12.6 Updatebuild126163
ZohocorpManageengine Opmanager Version12.6 Updatebuild126164
ZohocorpManageengine Opmanager Version12.6 Updatebuild126165
ZohocorpManageengine Opmanager Version12.6 Updatebuild126166
ZohocorpManageengine Opmanager Version12.6 Updatebuild126167
ZohocorpManageengine Opmanager Version12.6 Updatebuild126168
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126001
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126002
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126100
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126103
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126104
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126107
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126113
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126117
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126119
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126122
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126139
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126140
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126141
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126154
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126155
ZohocorpManageengine Opmanager Plus Version12.6 Updatebuild126264
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126001
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126002
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126100
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126103
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126104
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126107
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126113
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126117
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126119
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126122
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126139
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126140
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126141
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126154
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126155
ZohocorpManageengine Opmanager Msp Version12.6 Updatebuild126264
Zu dieser CVE wurde keine CISA KEV oder CERT.AT-Warnung gefunden.
EPSS Metriken
Type Source Score Percentile
EPSS FIRST.org 2.02% 0.83
CVSS Metriken
Source Base Score Exploit Score Impact Score Vector string
nvd@nist.gov 5.4 2.8 2.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:L/A:N
talos-cna@cisco.com 5.8 1.6 3.7
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
CWE-611 Improper Restriction of XML External Entity Reference

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.