← volver
CVE-2024-42185

HCL BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks

CVSS 2.5 LOWEPSS 0.1%CWE-611
Vexday Risk Score
8Bajo
Decisión SSVC (CISA)
Track
Sin señal de explotación → monitorear
CVSS 2.5EPSS 0.1%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
23 ene 2025Publicada en NVD
Recomendación: Monitorear — sin señal de explotación por ahora.
BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues including denial of service and unauthorized access.
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:C/C:L/I:N/A:N

¿Quieres saber si tu infraestructura está expuesta a esto?

Hablar con TrueHacking →