VulnerabilityModified
CVE-2021-28684
The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack).
MEDIUM 4.3EPSS 0.92%
Does this matter?
Lower severity and a low EPSS score (0.92%). Track it; it rarely justifies an emergency change on its own.
Description
The XML parser used in ConeXware PowerArchiver before 20.10.02 allows processing of external entities, which might lead to exfiltration of local files over the network (via an XXE attack).
- CVSS 3.1
- 4.3 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 0.92% probability · 58th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-611
- Affected
- powerarchiver/powerarchiver
- Source
- cve@mitre.org
References
- https://peterka.tech/blog/posts/cve-2021-28684/Exploit, Third Party Advisory
- https://www.powerarchiver.comProduct
- https://peterka.tech/blog/posts/cve-2021-28684/Exploit, Third Party Advisory
- https://www.powerarchiver.comProduct
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.