CVE-2021-20839

MEDIUMCVSS 6.5/10EPSS 1.10%

Last modified

CVE-2021-20839 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition to the other servers by processing a specially crafted XML document.. EPSS estimates a 1.10% chance of exploitation in the next 30 days.

Description

Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition to the other servers by processing a specially crafted XML document.

Metrics

CVSS 3.1
6.5/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Probability
1.10%

61.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
AntennahouseOffice Server Document Converter< 5.2
AntennahouseOffice Server Document Converter5.2
AntennahouseOffice Server Document Converter6.0
AntennahouseOffice Server Document Converter6.1
AntennahouseOffice Server Document Converter7.0
AntennahouseOffice Server Document Converter7.1
AntennahouseOffice Server Document Converter7.2

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2021-20839?
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition to the other servers by processing a specially crafted XML document.
How severe is CVE-2021-20839?
CVE-2021-20839 has a CVSS score of 6.5/10 (MEDIUM severity). The EPSS model estimates a 1.10% probability of exploitation in the next 30 days.
How do I fix CVE-2021-20839?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2021-20839?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST