Lucene search

K
cveMitreCVE-2019-13176
HistoryAug 08, 2019 - 2:15 p.m.

CVE-2019-13176

2019-08-0814:15:11
CWE-611
mitre
web.nvd.nist.gov
30
cve-2019-13176
3cx phone system
xxe vulnerability
ssrf
nvd

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.006

Percentile

78.3%

An issue was discovered in the 3CX Phone system (web) management console 12.5.44178.1002 through 12.5 SP2. The Content.MainForm.wgx component is affected by XXE via a crafted XML document in POST data. There is potential to use this for SSRF (reading local files, outbound HTTP, and outbound DNS).

Affected configurations

Nvd
Node
3cx3cxMatch12.5sp1
OR
3cx3cxMatch12.5sp2
OR
3cx3cxMatch12.5.44178.1002
VendorProductVersionCPE
3cx3cx12.5cpe:2.3:a:3cx:3cx:12.5:sp1:*:*:*:*:*:*
3cx3cx12.5cpe:2.3:a:3cx:3cx:12.5:sp2:*:*:*:*:*:*
3cx3cx12.5.44178.1002cpe:2.3:a:3cx:3cx:12.5.44178.1002:*:*:*:*:*:*:*

CVSS2

5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:L/Au:N/C:P/I:N/A:N

CVSS3

7.5

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

AI Score

7.3

Confidence

High

EPSS

0.006

Percentile

78.3%

Related for CVE-2019-13176