CVE-2014-0644
EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE)…
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 53.3%, higher than 99% of all known CVEs. Patch or mitigate before the next change window.
Description
EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, as demonstrated by reading the /etc/shadow file.
- CVSS 2.0
- 7.8 HIGHAV:N/AC:L/Au:N/C:C/I:N/A:N
- EPSS
- 53.34% probability · 99th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-200
- Affected
- emc/cloud tiering appliance software · emc/cloud tiering appliance
- Source
- security_alert@emc.com
References
- http://archives.neohapsis.com/archives/bugtraq/2014-04/0094.html
- http://seclists.org/fulldisclosure/2014/Mar/426
- https://gist.github.com/brandonprry/9895721
- http://archives.neohapsis.com/archives/bugtraq/2014-04/0094.html
- http://seclists.org/fulldisclosure/2014/Mar/426
- https://gist.github.com/brandonprry/9895721
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.