CVE-2023-52425
published 2024-02-04CVE-2023-52425: libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which…
PriorityP339high7.5CVSS 3.1
AVNACLPRNUINSUCNINAH
EPSS
1.81%
76.2th percentile
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
Affected
12 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| debian | expat | < expat 2.5.0-1+deb12u2 (bookworm) | expat 2.5.0-1+deb12u2 (bookworm) |
| debian | libxmltok | < expat 2.5.0-1+deb12u2 (bookworm) | expat 2.5.0-1+deb12u2 (bookworm) |
| libexpat_project | libexpat | <= 2.5.0 | — |
| msrc | azl3_expat_2.5.0-1_on_azure_linux_3.0 | — | — |
| msrc | azl3_expat_2.6.2-1_on_azure_linux_3.0 | — | — |
| msrc | azure_linux_3.0_arm | — | — |
| msrc | azure_linux_3.0_x64 | — | — |
| msrc | cbl2_expat_2.5.0-1_on_cbl_mariner_2.0 | — | — |
| msrc | cbl2_expat_2.6.2-2_on_cbl_mariner_2.0 | — | — |
| msrc | cbl_mariner_2.0_arm | — | — |
| msrc | cbl_mariner_2.0_x64 | — | — |
| paloalto | pan-os | — | — |
CVSS provenance
nvdv3.17.5HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
osv7.5HIGH
vendor_debian7.5HIGH
vendor_msrc7.5HIGH
vendor_oracle7.5HIGH
vendor_redhat7.5HIGH
vendor_ubuntu7.5HIGH
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2018-6594 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
Palo Alto
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
vendor_paloalto·2025-07-09·CVSS 7.5
CVE-2023-38546 [HIGH] PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
PAN-SA-2025-0012 Informational Bulletin: OSS CVEs Fixed in PAN-OS
The Palo Alto Networks Product Security Assurance team has evaluated the following open source software (OSS) CVEs as they relate to PAN-OS. While it was not determined that these CVEs have any significant impact on PAN-OS, they have been fixed out of an abundance of caution. CVE Summary CVE-2018-6594 This CVE is fixed in PAN-OS 10.2.17, 11.1.11, 11.2.8, 12.1.2, and all later versions of PAN-OS CVE-2018-25032 This CVE is fixed in PAN-OS 10.1.7, 10.2.2, and all later versions of PAN-OS CVE-2019-5827 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13750 This CVE is fixed in PAN-OS 11.1.4, and all later versions of PAN-OS. CVE-2019-13751 This CVE is fixed in PAN-OS 11.1.4, and all later versions
CISA ICS
Siemens SINEC NMS
cisa_ics·2024-08-15·CVSS 7.0
[HIGH] Siemens SINEC NMS
ICS Advisory
##
Siemens SINEC NMS
Release DateAugust 15, 2024
Alert CodeICSA-24-228-06
Related topics:
Industrial Control System Vulnerabilities, Industrial Control Systems
As of January 10, 2023, CISA will no longer be updating ICS security advisories for Siemens product vulnerabilities beyond the initial advisory. For the most up-to-date information on vulnerabilities in this advisory, please see Siemens' ProductCERT Security Advisories (CERT Services | Services | Siemens Global).
View CSAF
## 1. EXECUTIVE SUMMARY
- CVSS v4 9.4
- ATTENTION: Exploitable remotely/low attack complexity
- Vendor: Siemens
- Equipment: SINEC NMS
- Vulnerabilities: Use After Free, Improper Input Validation, Deserialization of Untrusted Data, Improper Restriction of Operations
Oracle
Oracle Oracle Communications Risk Matrix: Automated Test Suite Framework (LibExpat) — CVE-2023-52425
vendor_oracle·2024-07-15·CVSS 7.5
CVE-2023-52425 [HIGH] Oracle Oracle Communications Risk Matrix: Automated Test Suite Framework (LibExpat) — CVE-2023-52425
Oracle Oracle Communications Risk Matrix: Automated Test Suite Framework (LibExpat) vulnerability
CVE: CVE-2023-52425
CVSS: 7.5
Protocol: HTTP
Remote exploit: Yes
Affected versions: Network
Advisory: cpujul2024 (JUL 2024)
Ubuntu
Expat vulnerabilities
vendor_ubuntu·2024-03-14·CVSS 7.5
CVE-2024-28757 [HIGH] Expat vulnerabilities
Title: Expat vulnerabilities
Summary: Expat could be made to crash if it received specially crafted
input.
It was discovered that Expat could be made to consume large amounts of
resources. If a user or automated system were tricked into processing
specially crafted input, an attacker could possibly use this issue to cause
a denial of service. (CVE-2023-52425, CVE-2024-28757)
Instructions: In general, a standard system update will make all the necessary changes.
Microsoft
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
vendor_msrc·2024-02-13·CVSS 7.5
CVE-2023-52425 [HIGH] CWE-400 libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
FAQ: Is Azure Linux the only Microsoft product that includes this open-source library and is therefore potentially affected by this vulnerability?
One of the main benefits to our customers who choose to use the Azure Linux distro is the commitment to keep it up to date with the most recent and most secure versions of the open source libraries with which the distro is composed. Microsoft is committed to transparency in this work which is why we began publishing CSAF/VEX in October 2025. See this blog post for more information. If impact to additional products is identified, we will update the CVE to refle
Red Hat
expat: parsing large tokens can trigger a denial of service
vendor_redhat·2024-02-04·CVSS 7.5
CVE-2023-52425 [HIGH] CWE-400 expat: parsing large tokens can trigger a denial of service
expat: parsing large tokens can trigger a denial of service
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
A flaw was found in Expat (libexpat). When parsing a large token that requires multiple buffer fills to complete, Expat has to re-parse the token from start numerous times. This process may trigger excessive resource consumption, leading to a denial of service.
Statement: The identified flaw in Expat presents a moderate severity issue due to its potential to facilitate resource exhaustion attacks, particularly in scenarios involving parsing large tokens requiring multiple buffer fills. As Expat repeatedly re-parses such tokens from the beginni
Debian
CVE-2023-52425: expat - libexpat through 2.5.0 allows a denial of service (resource consumption) because...
vendor_debian·2023·CVSS 7.5
CVE-2023-52425 [HIGH] CVE-2023-52425: expat - libexpat through 2.5.0 allows a denial of service (resource consumption) because...
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
Scope: local
bookworm: resolved (fixed in 2.5.0-1+deb12u2)
bullseye: resolved (fixed in 2.2.10-2+deb11u6)
forky: resolved (fixed in 2.6.0-1)
sid: resolved (fixed in 2.6.0-1)
trixie: resolved (fixed in 2.6.0-1)
OSV
expat vulnerabilities
osv·2024-03-14·CVSS 7.5
CVE-2023-52425 [HIGH] expat vulnerabilities
expat vulnerabilities
It was discovered that Expat could be made to consume large amounts of
resources. If a user or automated system were tricked into processing
specially crafted input, an attacker could possibly use this issue to cause
a denial of service. (CVE-2023-52425, CVE-2024-28757)
GHSA
GHSA-gh68-jm46-84rf: libexpat through 2
ghsa_unreviewed·2024-02-04
CVE-2023-52425 [HIGH] CWE-400 GHSA-gh68-jm46-84rf: libexpat through 2
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
OSV
CVE-2023-52425: libexpat through 2
osv·2024-02-04·CVSS 7.5
CVE-2023-52425 [HIGH] CVE-2023-52425: libexpat through 2
libexpat through 2.5.0 allows a denial of service (resource consumption) because many full reparsings are required in the case of a large token for which multiple buffer fills are needed.
No detection rules found.
No public exploits indexed.
http://www.openwall.com/lists/oss-security/2024/03/20/5https://github.com/libexpat/libexpat/pull/789https://lists.debian.org/debian-lts-announce/2024/04/msg00006.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNUBSGZFEZOBHJFTAD42SAN4ATW2VEMV/https://security.netapp.com/advisory/ntap-20240614-0003/http://www.openwall.com/lists/oss-security/2024/03/20/5https://github.com/libexpat/libexpat/pull/789https://lists.debian.org/debian-lts-announce/2024/04/msg00006.htmlhttps://lists.debian.org/debian-lts-announce/2024/09/msg00036.htmlhttps://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/https://lists.fedoraproject.org/archives/list/package-announce%40lists.fedoraproject.org/message/WNUBSGZFEZOBHJFTAD42SAN4ATW2VEMV/https://lists.fedoraproject.org/archives/list/[email protected]/message/PNRIHC7DVVRAIWFRGV23Y6UZXFBXSQDB/https://security.netapp.com/advisory/ntap-20240614-0003/
2024-02-04
Published