Vulnerabilities > CVE-2023-23595 - XXE vulnerability in Bluecatnetworks Device Registration Portal 2.2
Attack vector
NETWORK Attack complexity
LOW Privileges required
NONE Confidentiality impact
HIGH Integrity impact
NONE Availability impact
NONE Summary
BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A single-line file might contain credentials, such as "machine example.com login daniel password qwerty" in the documentation example for the .netrc file format. NOTE: 2.x versions are no longer supported. There is no available information about whether any later version is affected.
Vulnerable Configurations
Part | Description | Count |
---|---|---|
Application | 1 |