Lucene search

K
cvelistIcscertCVELIST:CVE-2021-43990
HistoryApr 20, 2022 - 3:30 p.m.

CVE-2021-43990 ICSA-22-109-03 FANUC ROBOGUIDE Simulation Platform

2022-04-2015:30:28
CWE-611
icscert
www.cve.org
3
fanuc roboguide
network-based attack
xml payload
external entity reference

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:H

EPSS

0.001

Percentile

36.6%

The affected product is vulnerable to a network-based attack by threat actors supplying a crafted, malicious XML payload designed to trigger an external entity reference call.

CNA Affected

[
  {
    "product": "ROBOGUIDE",
    "vendor": "FANUC",
    "versions": [
      {
        "lessThan": "v9.40083.00.05 (Rev T)",
        "status": "affected",
        "version": "All",
        "versionType": "custom"
      }
    ]
  }
]

CVSS3

6.1

Attack Vector

NETWORK

Attack Complexity

HIGH

Privileges Required

NONE

User Interaction

REQUIRED

Scope

CHANGED

Confidentiality Impact

NONE

Integrity Impact

NONE

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:N/I:N/A:H

EPSS

0.001

Percentile

36.6%

Related for CVELIST:CVE-2021-43990