CVE-2018-10832
PoC ×2—CVSS 3.0
5.5 medium
EPSS
6%p93
Published
()
Modified
Description
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in ModbusPal, will return the contents of any local files to a remote attacker.
- Vendors
- modbuspal project
- Products
- modbuspal
- Weakness
- CWE-611
- Vector
- CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
In the news0 stories
No ingested article mentions this CVE yet.