CVE-2018-1000828

CRITICALCVSS 9/10EPSS 1.33%

Last modified

CVE-2018-1000828 is a critical-severity vulnerability rated 9/10 on the CVSS scale. FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the middle the call to update the software.. EPSS estimates a 1.33% chance of exploitation in the next 30 days.

Description

FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the middle the call to update the software.

Metrics

CVSS 3.1
9/10

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H

EPSS Probability
1.33%

67.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
FrostwireFrostwire1.9.9Build246
FrostwireFrostwire2.0.7Build263
FrostwireFrostwire6.1.6Build166
FrostwireFrostwire6.1.7Build168
FrostwireFrostwire6.1.8Build169
FrostwireFrostwire6.1.9Build172
FrostwireFrostwire6.2.0Build173
FrostwireFrostwire6.2.1Build175
FrostwireFrostwire6.2.2Build176
FrostwireFrostwire6.2.3Build177
FrostwireFrostwire6.2.4Build179
FrostwireFrostwire6.3.0Build180
FrostwireFrostwire6.3.1Build186
FrostwireFrostwire6.3.2Build187
FrostwireFrostwire6.3.3Build189
FrostwireFrostwire6.3.4Build193
FrostwireFrostwire6.3.5Build195
FrostwireFrostwire6.3.6Build201
FrostwireFrostwire6.3.7Build203
FrostwireFrostwire6.4.0Build207
FrostwireFrostwire6.4.1Build209
FrostwireFrostwire6.4.2Build212
FrostwireFrostwire6.4.3Build214
FrostwireFrostwire6.4.4Build215
FrostwireFrostwire6.4.5Build218
FrostwireFrostwire6.4.6Build223
FrostwireFrostwire6.4.7Build228
FrostwireFrostwire6.4.8Build230
FrostwireFrostwire6.4.9Build235
FrostwireFrostwire6.5.0Build236
FrostwireFrostwire6.5.1Build238
FrostwireFrostwire6.5.2Build239
FrostwireFrostwire6.5.3Build240
FrostwireFrostwire6.5.4Build241
FrostwireFrostwire6.5.5Build242
FrostwireFrostwire6.5.8Build244
FrostwireFrostwire6.5.9Build246
FrostwireFrostwire6.6.0Build248
FrostwireFrostwire6.6.1Build249
FrostwireFrostwire6.6.2Build250
FrostwireFrostwire6.6.3Build252
FrostwireFrostwire6.6.4Build256
FrostwireFrostwire6.6.5Build257
FrostwireFrostwire6.6.6Build258
FrostwireFrostwire6.6.7Build529
FrostwireFrostwire6.6.8Build260
FrostwireFrostwire6.7.0Build261
FrostwireFrostwire6.7.1Build266
FrostwireFrostwire6.7.2Build269
FrostwireFrostwire6.7.3Build271

Showing 50 of 51 affected configurations. See NVD for the full list.

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2018-1000828?
FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the middle the call to update the software.
How severe is CVE-2018-1000828?
CVE-2018-1000828 has a CVSS score of 9/10 (CRITICAL severity). The EPSS model estimates a 1.33% probability of exploitation in the next 30 days.
How do I fix CVE-2018-1000828?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2018-1000828?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST