VulnerabilityModified
CVE-2018-10832
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack.
MEDIUM 5.5EPSS 5.94%
Does this matter?
Lower severity and a low EPSS score (5.94%). Track it; it rarely justifies an emergency change on its own.
Description
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in ModbusPal, will return the contents of any local files to a remote attacker.
- CVSS 3.0
- 5.5 MEDIUMCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 5.94% probability · 93th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- modbuspal project/modbuspal
- Source
- cve@mitre.org
References
- http://packetstormsecurity.com/files/147573/ModbusPal-1.6b-XML-External-Entity-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44607/Exploit, Third Party Advisory, VDB Entry
- http://packetstormsecurity.com/files/147573/ModbusPal-1.6b-XML-External-Entity-Injection.htmlExploit, Third Party Advisory, VDB Entry
- https://www.exploit-db.com/exploits/44607/Exploit, Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.