Vulnerabilities > CVE-2020-24052 - XML Entity Expansion vulnerability in Moog Exvf5C-2 Firmware and Exvp7C2-3 Firmware

047910
CVSS 6.4 - MEDIUM
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
PARTIAL
Integrity impact
NONE
Availability impact
PARTIAL
network
low complexity
moog
CWE-776

Summary

Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML request.

Vulnerable Configurations

Part Description Count
OS
Moog
2
Hardware
Moog
2