CVE-2017-6323
Last modified
CVE-2017-6323 is a vulnerability of currently unknown severity. The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located, and other system impacts.. EPSS estimates a 0.52% chance of exploitation in the next 30 days.
Description
The Symantec Management Console prior to ITMS 8.1 RU1, ITMS 8.0_POST_HF6, and ITMS 7.6_POST_HF7 has an issue whereby XML input containing a reference to an external entity is processed by a weakly configured XML parser. This attack may lead to the disclosure of confidential data, denial of service, server side request forgery, port scanning from the perspective of the machine where the parser is located, and other system impacts.
Metrics
Weakness Enumeration
Affected Software
| Vendor | Product | Versions | Update |
|---|---|---|---|
| Symantec | Management Console | < 8.1 | — |
| Symantec | Management Console | 7.6 | Hf7 |
| Symantec | Management Console | 8.0 | Hf6 |
References
- http://www.securityfocus.com/bid/98621Third Party Advisory, VDB Entry
- http://www.securityfocus.com/bid/98621Third Party Advisory, VDB Entry
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2017-6323?
How severe is CVE-2017-6323?
How do I fix CVE-2017-6323?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2017
- CVE-2017-6315Astaro Security Gateway (aka ASG) 7 allows remote attackers …
- CVE-2017-6316Citrix NetScaler SD-WAN devices through v9.1.2.26.561201 all…9.8
- CVE-2017-6317Memory leak in the add_shader_program function in vrend_rend…
- CVE-2017-6318saned in sane-backends 1.0.25 allows remote attackers to obt…
- CVE-2017-6319The dex_parse_debug_item function in libr/bin/p/bin_dex.c in…
- CVE-2017-6320A remote command injection vulnerability exists in the Barra…8.8
- CVE-2017-6324The Symantec Messaging Gateway, when processing a specific e…
- CVE-2017-6325The Symantec Messaging Gateway can encounter a file inclusio…
- CVE-2017-6326The Symantec Messaging Gateway can encounter an issue of rem…
- CVE-2017-6327The Symantec Messaging Gateway before 10.6.3-267 can encount…8.8
- CVE-2017-6328The Symantec Messaging Gateway before 10.6.3-267 can encount…
- CVE-2017-6329Symantec VIP Access for Desktop prior to 2.2.4 can be suscep…
Are you affected by CVE-2017-6323?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
