CVE-2014-0644
EMC Cloud Tiering Appliance Software - Information Disclosure
Title source: ruleDescription
EMC Cloud Tiering Appliance (CTA) 10 through SP1 allows remote attackers to read arbitrary files via an api/login request containing an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue, as demonstrated by reading the /etc/shadow file.
Exploits (2)
exploitdb
WORKING POC
by Brandon Perry · textwebappsmultiple
https://www.exploit-db.com/exploits/32623
metasploit
WORKING POC
rubypoc
https://github.com/rapid7/metasploit-framework/blob/master/modules/auxiliary/gather/emc_cta_xxe.rb
Scores
EPSS
0.7402
EPSS Percentile
98.8%
Details
CWE
CWE-200
Status
published
Products (2)
emc/cloud_tiering_appliance
emc/cloud_tiering_appliance_software
10.0 (2 CPE variants)
Published
Apr 17, 2014
Tracked Since
Feb 18, 2026