Lucene search

K
cveJpcertCVE-2024-21796
HistoryJan 24, 2024 - 2:15 a.m.

CVE-2024-21796

2024-01-2402:15:07
CWE-611
jpcert
web.nvd.nist.gov
16
cve-2024-21796
xxe vulnerability
electronic deliverables creation support tool
ver1.0.4
nvd
security advisory

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

20.7%

Electronic Deliverables Creation Support Tool (Construction Edition) prior to Ver1.0.4 and Electronic Deliverables Creation Support Tool (Design & Survey Edition) prior to Ver1.0.4 improperly restrict XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the system may be read by an attacker.

Affected configurations

Nvd
Vulners
Node
dfegelectronic_deliverables_creation_support_toolRange<1.0.4construction
OR
dfegelectronic_deliverables_creation_support_toolRange<1.0.4design_\&_survey
VendorProductVersionCPE
dfegelectronic_deliverables_creation_support_tool*cpe:2.3:a:dfeg:electronic_deliverables_creation_support_tool:*:*:*:*:*:construction:*:*
dfegelectronic_deliverables_creation_support_tool*cpe:2.3:a:dfeg:electronic_deliverables_creation_support_tool:*:*:*:*:*:design_\&_survey:*:*

CNA Affected

[
  {
    "vendor": "Ministry of Defense",
    "product": "Electronic Deliverables Creation Support Tool (Construction Edition)",
    "versions": [
      {
        "version": "prior to Ver1.0.4",
        "status": "affected"
      }
    ]
  },
  {
    "vendor": "Ministry of Defense",
    "product": "Electronic Deliverables Creation Support Tool (Design & Survey Edition)",
    "versions": [
      {
        "version": "prior to Ver1.0.4",
        "status": "affected"
      }
    ]
  }
]

CVSS3

5.5

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

20.7%

Related for CVE-2024-21796