CVE-2014-0644

EMC Cloud Tiering Appliance Software - Information Disclosure

Title source: rule

Description

EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, as demonstrated by reading the /etc/shadow file.

Exploits (2)

exploitdb WORKING POC
by Brandon Perry · textwebappsmultiple
https://www.exploit-db.com/exploits/32623
metasploit WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/emc_cta_xxe.rb

Scores

EPSS 0.7402
EPSS Percentile 98.8%

Details

CWE
CWE-200
Status published
Products (2)
emc/cloud_tiering_appliance
emc/cloud_tiering_appliance_software 10.0 (2 CPE variants)
Published Apr 17, 2014
Tracked Since Feb 18, 2026