CVE-2023-23595
Description
BlueCat Device Registration Portal 2.2 allows XXE attacks that exfiltrate single-line files. A single-line file might contain credentials, such as "machine example.com login daniel password qwerty" in the documentation example for the .netrc file format. NOTE: 2.x versions are no longer supported. There is no available information about whether any later version is affected.
References
ProductVendor Advisory
ExploitThird Party Advisory
Technical DescriptionThird Party Advisory
CvssV3 impact
Could not find any metrics
CvssV2 impact
Could not find any metrics