CVE-2020-27017XML External Entity (XXE) Injection in Interscan Messaging Security Virtual Appliance

Severity
4.9MEDIUMNVD
EPSS
1.0%
top 22.99%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedNov 9
Latest updateMay 24

Description

Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 9.1 is vulnerable to an XML External Entity Processing (XXE) vulnerability which could allow an authenticated administrator to read arbitrary local files. An attacker must already have obtained product administrator/root privileges to exploit this vulnerability.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:NExploitability: 1.2 | Impact: 3.6

🔴Vulnerability Details

2
GHSA
GHSA-m5fq-fj2f-7888: Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 92022-05-24
CVEList
CVE-2020-27017: Trend Micro InterScan Messaging Security Virtual Appliance (IMSVA) 92020-11-09
CVE-2020-27017 — XML External Entity (XXE) Injection | cvebase