ZeroHour

CVE-2018-10832

PoC ×2
CVSS 3.0
5.5 medium
EPSS
6%p93
Published
()
Modified
Description

ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in ModbusPal, will return the contents of any local files to a remote attacker.

Vendors
modbuspal project
Products
modbuspal
Weakness
CWE-611
Vector
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.