CVE-2021-44477

HIGH

GE ToolBoxST < 07.09.07c - XML External Entity Injection via DTD Parameter Entities

Title source: llm
STIX 2.1

Description

GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project/template file.

References (1)

Core 1
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_confirm
https://www.cisa.gov/uscert/ics/advisories/icsa-22-025-01

Scores

CVSS v3 7.5
EPSS 0.0105
EPSS Percentile 59.8%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-611
Status published
Products (1)
ge/toolboxst < 07.09.07c
Published Mar 25, 2022
Tracked Since Feb 18, 2026