7.4
CVE-2026-71375
- EPSS 0.25%
- Veröffentlicht 08.09.2026 07:56:36
- Zuletzt bearbeitet 08.09.2026 14:18:34
- Erkennungen
XXE Vulnerability in Cosminexus Component Container
Improper restriction of XML external entity reference vulnerability in Cosminexus Component Container. This issue affects Cosminexus Component Container: from 11-70-01 before 11-70-03, from 11-60 before 11-60-03, from 11-50 through 11-50-03, from 11-40 through 11-40-03, from 11-30 through 11-30-08, from 11-20 before 11-20-10, from 11-10 through 11-10-11, from 11-00 before 11-00-13, from 09-87 before 09-87-10, from 09-80 before 09-80-05, from 09-70 before 09-70-28, from 09-50 through 09-50-22, and from 09-00 through 09-00-18.
Daten sind bereitgestellt durch das CVE Programm von einer CVE Numbering Authority (CNA) (Unstrukturiert).
HerstellerHitachi
≫
Produkt
Cosminexus Component Container
Default Statusunaffected
Version
11-70-01
Version <
11-70-03
Status
affected
Version
11-60
Version <
11-60-03
Status
affected
Version <=
11-50-03
Version
11-50
Status
affected
Version <=
11-40-03
Version
11-40
Status
affected
Version <=
11-30-08
Version
11-30
Status
affected
Version
11-20
Version <
11-20-10
Status
affected
Version <=
11-10-11
Version
11-10
Status
affected
Version
11-00
Version <
11-00-13
Status
affected
Version
09-87
Version <
09-87-10
Status
affected
Version
09-80
Version <
09-80-05
Status
affected
Version
09-70
Version <
09-70-28
Status
affected
Version <=
09-50-22
Version
09-50
Status
affected
Version <=
09-00-18
Version
09-00
Status
affected
VulnDex Vulnerability Enrichment
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.25% | 0.158 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| hirt@hitachi.co.jp | 7.4 | 2.2 | 5.2 |
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:N/A:H
|
CWE-611 Improper Restriction of XML External Entity Reference
The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
https://www.hitachi.com/products/it/software/security/info/vuls/hitachi-sec-2026-131/index.html