CVE-2020-24052

Severity CVSS v4.0:
Pending analysis
Type:
CWE-611 Improper Restriction of XML External Entity Reference ('XXE')
Publication date:
21/08/2020
Last modified:
21/07/2021

Description

Several XML External Entity (XXE) vulnerabilities in the Moog EXO Series EXVF5C-2 and EXVP7C2-3 units allow remote unauthenticated users to read arbitrary files via a crafted Document Type Definition (DTD) in an XML request.

Vulnerable products and versions

CPE From Up to
cpe:2.3:o:moog:exvf5c-2_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:moog:exvf5c-2:-:*:*:*:*:*:*:*
cpe:2.3:o:moog:exvp7c2-3_firmware:-:*:*:*:*:*:*:*
cpe:2.3:h:moog:exvp7c2-3:-:*:*:*:*:*:*:*