ZeroHour

CVE-2019-10244

CVSS 3.0
7.5 high
EPSS
2%p78
Published
()
Modified
Description

In Eclipse Kura versions up to 4.0.0, the Web UI package and component services, the Artemis simple Mqtt component and the emulator position service (not part of the device distribution) could potentially be target of XXE attack due to an improper factory and parser initialisation.

Vendors
eclipse
Products
kura
Weakness
CWE-611
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

In the news

No ingested article mentions this CVE yet.