CVE-2016-8348

CRITICAL

Emerson Liebert SiteScan <6.5 - XSS

Title source: llm
STIX 2.1

Description

An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.

References (2)

Core 2
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_misc
https://ics-cert.us-cert.gov/advisories/ICSA-16-334-01
Third Party Advisory, VDB Entry vdb-entry x_refsource_bid
http://www.securityfocus.com/bid/94587

Scores

CVSS v3 9.8
EPSS 0.0352
EPSS Percentile 87.7%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-611
Status published
Products (2)
emerson/liebert_sitescan_web < 6.5
n/a/Emerson Liebert SiteScan 6.5, and prior Emerson Liebert SiteScan 6.5, and prior
Published Feb 13, 2017
Tracked Since Feb 18, 2026