CVE-2020-7572
CVE-2020-7572
Vexday Risk Score
3Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS —EPSS 1.8%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
19 Nov 2020Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
A CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists in EcoStruxure Building Operation WebReports V1.9 - V3.1 that could cause an authenticated remote user being able to inject arbitrary XML code and obtain disclosure of confidential data, denial of service, server side request forgery due to improper configuration of the XML parser.
Affected products
n/a · EcoStruxure Building Operation WebReports V1.9 - V3.1Want to know if your infrastructure is exposed to this?
Talk to TrueHacking →