Vulnerability Description
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in ModbusPal, will return the contents of any local files to a remote attacker.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Modbuspal Project | Modbuspal | 1.6 |
Related Weaknesses (CWE)
References
- http://packetstormsecurity.com/files/147573/ModbusPal-1.6b-XML-External-Entity-IExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/44607/ExploitThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/147573/ModbusPal-1.6b-XML-External-Entity-IExploitThird Party AdvisoryVDB Entry
- https://www.exploit-db.com/exploits/44607/ExploitThird Party AdvisoryVDB Entry
FAQ
What is CVE-2018-10832?
CVE-2018-10832 is a vulnerability with a CVSS score of 5.5 (MEDIUM). ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injec...
How severe is CVE-2018-10832?
CVE-2018-10832 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2018-10832?
Check the references section above for vendor advisories and patch information. Affected products include: Modbuspal Project Modbuspal.