CVE-2015-0581
published 2015-01-28CVE-2015-0581: The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and…
PriorityP337high7.5CVSS 2.0
AVNACLAuSCCINAP
EPSS
2.37%
81.9th percentile
The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related to an XML External Entity (XXE) issue, aka Bug ID CSCup92880.
Affected
2 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| cisco | prime_service_catalog | <= 10.0 | — |
| cisco | prime_service_catalog_xml_external_entity_processing | — | — |
CVSS provenance
nvdv2.07.5HIGHAV:N/AC:L/Au:S/C:C/I:N/A:P
vendor_cisco7.0HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-34hv-w8p5-75g4: The XML parser in Cisco Prime Service Catalog before 10
ghsa_unreviewed·2022-05-17
CVE-2015-0581 [HIGH] GHSA-34hv-w8p5-75g4: The XML parser in Cisco Prime Service Catalog before 10
The XML parser in Cisco Prime Service Catalog before 10.1 allows remote authenticated users to read arbitrary files or cause a denial of service (CPU and memory consumption) via an external entity declaration in conjunction with an entity reference, as demonstrated by reading private keys, related to an XML External Entity (XXE) issue, aka Bug ID CSCup92880.
Cisco
Cisco Prime Service Catalog XML External Entity Processing Vulnerability
vendor_cisco·2015-01-28·CVSS 7.0
CVE-2015-0581 [HIGH] CWE-20 Cisco Prime Service Catalog XML External Entity Processing Vulnerability
Cisco Prime Service Catalog XML External Entity Processing Vulnerability
A vulnerability in the configuration of the XML parser of Cisco Prime Service Catalog could allow an authenticated, remote attacker to access sensitive data stored on the host operating system or cause system resource consumption that could cause a denial of service condition.
Cisco has released software updates that address this vulnerability.
This advisory is available at the following link:
https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150128-psc-xmlee
Cisco
Cisco Prime Service Catalog XML External Entity Processing Vulnerability
vendor_cisco
CVE-2015-0581 Cisco Prime Service Catalog XML External Entity Processing Vulnerability
CVE-2015-0581: Cisco Prime Service Catalog XML External Entity Processing Vulnerability
A vulnerability in the configuration of the XML parser of Cisco Prime Service Catalog could allow an authenticated, remote attacker to access sensitive data stored on the host operating system or cause system resource consumption that could cause a denial of service condition. Cisco has released software updates that address this vulnerability. This advisory is available at the following link: https://sec.cloudapps.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150128-psc-xmlee
CWE: CWE-20, CWE-20
Bug IDs: CSCup92880, CSCup92880
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150128-psc-xmleehttp://www.securityfocus.com/bid/72350http://www.securitytracker.com/id/1031658http://tools.cisco.com/security/center/content/CiscoSecurityAdvisory/cisco-sa-20150128-psc-xmleehttp://www.securityfocus.com/bid/72350http://www.securitytracker.com/id/1031658
2015-01-28
Published