Vulnerabilities > CVE-2020-24052 - XXE vulnerability in Moog Exvf5C-2 Firmware and Exvp7C2-3 Firmware

047910
CVSS 9.1 - CRITICAL
Attack vector
NETWORK
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
HIGH
Integrity impact
NONE
Availability impact
HIGH
network
low complexity
moog
CWE-611
critical

Summary

Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML request.

Vulnerable Configurations

Part Description Count
OS
Moog
2
Hardware
Moog
2