Vulnerabilities > CVE-2018-3881 - XXE vulnerability in Focalscope 2416

047910
CVSS 9.4 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
LOW
Availability impact
HIGH
network
low complexity
focalscope
CWE-611
critical

Summary

An exploitable unauthenticated XML external injection vulnerability was identified in FocalScope v2416. A unauthenticated attacker could submit a specially crafted web request to FocalScope's server that could cause an XXE, and potentially result in data compromise.

Vulnerable Configurations

Part Description Count
Application
Focalscope
1

Talos

idTALOS-2018-0559
last seen2019-05-29
published2018-07-20
reporterTalos Intelligence
sourcehttp://www.talosintelligence.com/vulnerability_reports/TALOS-2018-0559
titleFocalScope XML External Entity Injection Vulnerability