CVE-2018-5789

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
05/02/2018
Last modified:
22/02/2018

Description

An issue was discovered in Extreme Networks ExtremeWireless WiNG 5.x before 5.8.6.9 and 5.9.x before 5.9.1.3. There is a Remote, Unauthenticated XML Entity Expansion Denial of Service on the WiNG Access Point / Controller via crafted XML entities to the Web User Interface.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:extremewireless:wing:*:*:*:*:*:*:*:* 5.0 (including) 5.8.6.9 (excluding)
cpe:2.3:o:extremewireless:wing:*:*:*:*:*:*:*:* 5.9.0 (including) 5.9.1.3 (excluding)