CVE-2024-21765
CVE-2024-21765
Vexday Risk Score
13Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 5.5EPSS 0.2%KEV nãoPoC —Nuclei —Metasploit —Patch —
Ciclo de vida
24 jan 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
Electronic Delivery Check System (Doboku) Ver.18.1.0 and earlier, Electronic Delivery Check System (Dentsu) Ver.12.1.0 and earlier, Electronic Delivery Check System (Kikai) Ver.10.1.0 and earlier, and Electronic delivery item Inspection Support SystemVer.4.0.31 and earlier improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Produtos afetados
Ministry of Land, Infrastructure, Transport and Tourism, Japan · Electronic Delivery Check System (Dentsu)Ministry of Land, Infrastructure, Transport and Tourism, Japan · Electronic Delivery Check System (Doboku)Ministry of Land, Infrastructure, Transport and Tourism, Japan · Electronic Delivery Check System (Kikai)Ministry of Land, Infrastructure, Transport and Tourism, Japan · Electronic delivery item Inspection Support SystemQuer saber se a sua infraestrutura está exposta a isto?
Falar com a TrueHacking →