Vulnerabilities > CVE-2019-13625 - XXE vulnerability in NSA Ghidra 9.0

047910
CVSS 9.4 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
NONE
Integrity impact
COMPLETE
Availability impact
COMPLETE
network
low complexity
nsa
CWE-611
critical

Summary

NSA Ghidra before 9.0.1 allows XXE when a project is opened or restored, or a tool is imported, as demonstrated by a project.prp file.

Vulnerable Configurations

Part Description Count
Application
Nsa
1