CVE-2020-3256
Cisco Hosted Collaboration Mediation Fulfillment XML External Expansion Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
A vulnerability in the web-based management interface of Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) Software could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. To exploit this vulnerability, an attacker would need administrative privileges on the Cisco HCM-F Software. The vulnerability is due to improper handling of XML External Entity (XXE) entries when parsing certain XML files. An attacker could exploit this vulnerability by sending malicious requests that contain references in XML entities to an affected system. A successful exploit could allow the attacker to retrieve files from the local system, resulting in the disclosure of sensitive information.
Una vulnerabilidad en la interfaz de administración basada en web del Cisco Hosted Collaboration Mediation Fulfillment (HCM-F) Software, podría permitir a un atacante remoto autenticado conseguir acceso de lectura a la información que es almacenada sobre un sistema afectado. Para explotar esta vulnerabilidad, un atacante necesitaría privilegios administrativos en el Cisco HCM-F Software. La vulnerabilidad es debido al manejo inapropiado de entradas XML External Entity (XXE) cuando se analizan determinados archivos XML. Un atacante podría explotar esta vulnerabilidad mediante el envío de peticiones maliciosas que contienen referencias en entidades XML hacia un sistema afectado. Una explotación con éxito podría permitir a un atacante recuperar archivos desde el sistema local, resultando una divulgación de información confidencial.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2019-12-12 CVE Reserved
- 2020-05-06 CVE Published
- 2024-01-22 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-611: Improper Restriction of XML External Entity Reference
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-hcmf-xxe-qqCMAUJ2 | 2020-05-12 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Cisco Search vendor "Cisco" | Hosted Collaboration Mediation Fulfillment Search vendor "Cisco" for product "Hosted Collaboration Mediation Fulfillment" | < 12.5\(1\)su2 Search vendor "Cisco" for product "Hosted Collaboration Mediation Fulfillment" and version " < 12.5\(1\)su2" | - |
Affected
|