MEDIUM · 5.8

CVE-2022-43473

A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a ...

Vulnerability Description

A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a malicious XML payload to trigger this vulnerability.

CVSS Score

5.8

MEDIUM

CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
Attack Vector
NETWORK
Attack Complexity
HIGH
Privileges Required
NONE
User Interaction
REQUIRED
Scope
CHANGED
Confidentiality
LOW
Integrity
LOW
Availability
LOW

Affected Products

VendorProductVersions
ZohocorpManageengine Opmanager< 12.6
ZohocorpManageengine Opmanager Plus< 12.6
ZohocorpManageengine Opmanager Msp< 12.6

Related Weaknesses (CWE)

References

FAQ

What is CVE-2022-43473?

CVE-2022-43473 is a vulnerability with a CVSS score of 5.8 (MEDIUM). A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve a ...

How severe is CVE-2022-43473?

CVE-2022-43473 has been rated MEDIUM with a CVSS base score of 5.8/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2022-43473?

Check the references section above for vendor advisories and patch information. Affected products include: Zohocorp Manageengine Opmanager, Zohocorp Manageengine Opmanager Plus, Zohocorp Manageengine Opmanager Msp.