CVE-2020-26981XML External Entity (XXE) Injection in Siemens Jt2go

Severity
6.5MEDIUMNVD
EPSS
0.4%
top 39.08%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 12
Latest updateMay 24

Description

A vulnerability has been identified in JT2Go (All versions < V13.1.0), Teamcenter Visualization (All versions < V13.1.0). When opening a specially crafted xml file, the application could disclose arbitrary files to remote attackers. This is because of the passing of specially crafted content to the underlying XML parser without taking proper restrictions such as prohibiting an external dtd. (ZDI-CAN-11890)

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages4 packages

CVEListV5siemens/teamcenter_visualizationAll versions < V13.1.0
NVDsiemens/jt2go< 13.1.0
CVEListV5siemens/jt2goAll versions < V13.1.0

🔴Vulnerability Details

2
GHSA
GHSA-cfxj-95gx-6rxg: A vulnerability has been identified in JT2Go (All Versions < V132022-05-24
CVEList
CVE-2020-26981: A vulnerability has been identified in JT2Go (All versions < V132021-01-12

📋Vendor Advisories

1
CISA ICS
Siemens JT2Go and Teamcenter Visualization (Update B)2021-02-09
CVE-2020-26981 — XML External Entity (XXE) Injection | cvebase