CVE-2024-21765
CVE-2024-21765
Vexday Risk Score
13Low
SSVC decision (CISA)
Track
No exploitation signal → monitor
CVSS 5.5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Lifecycle
24 Jan 2024Published on NVD
Recommendation: Monitor — no exploitation signal at the moment.
Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Support SystemVer.4.0.31 and earlier improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Affected products
Ministry of Land, Infrastructure, Transport and Tourism, Japan · Electronic Delivery Check System (Dentsu)Ministry of Land, Infrastructure, Transport and Tourism, Japan · Electronic Delivery Check System (Doboku)Ministry of Land, Infrastructure, Transport and Tourism, Japan · Electronic Delivery Check System (Kikai)Ministry of Land, Infrastructure, Transport and Tourism, Japan · Electronic delivery item Inspection Support SystemWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →