« Volver al listado

CVE-2023-6280

Estado: ModificadaAlta (7.5)—

An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network.

CVSS

Probabilidad de explotación (EPSS)

EPSS (Exploit Prediction Scoring System, de FIRST) estima la probabilidad de que una vulnerabilidad sea explotada en 30 días. Complementa a CVSS (impacto) y a CISA KEV (explotación confirmada).

Tecnologías afectadas (1)

CWE

Referencias

JSON original (NVD)

Mostrar
{
  "id": "CVE-2023-6280",
  "cveTags": [
    {
      "tags": [
        "unsupported-when-assigned"
      ],
      "sourceIdentifier": "cve-coordination@incibe.es"
    }
  ],
  "metrics": {
    "cvssMetricV31": [
      {
        "type": "Secondary",
        "source": "cve-coordination@incibe.es",
        "cvssData": {
          "scope": "CHANGED",
          "version": "3.1",
          "baseScore": 7.2,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:L",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "LOW",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "LOW"
        },
        "impactScore": 2.7,
        "exploitabilityScore": 3.9
      },
      {
        "type": "Primary",
        "source": "nvd@nist.gov",
        "cvssData": {
          "scope": "UNCHANGED",
          "version": "3.1",
          "baseScore": 7.5,
          "attackVector": "NETWORK",
          "baseSeverity": "HIGH",
          "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N",
          "integrityImpact": "NONE",
          "userInteraction": "NONE",
          "attackComplexity": "LOW",
          "availabilityImpact": "NONE",
          "privilegesRequired": "NONE",
          "confidentialityImpact": "HIGH"
        },
        "impactScore": 3.6,
        "exploitabilityScore": 3.9
      }
    ]
  },
  "affected": [
    {
      "source": "cve-coordination@incibe.es",
      "affectedData": [
        {
          "vendor": "52North",
          "product": "52North WPS",
          "versions": [
            {
              "status": "affected",
              "version": "0",
              "lessThan": "4.0.0-beta.11",
              "versionType": "custom"
            }
          ],
          "defaultStatus": "unaffected"
        }
      ]
    }
  ],
  "published": "2023-12-19T15:15:09.033",
  "references": [
    {
      "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/xml-external-entity-reference-52north-wps",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "cve-coordination@incibe.es"
    },
    {
      "url": "https://www.incibe.es/en/incibe-cert/notices/aviso/xml-external-entity-reference-52north-wps",
      "tags": [
        "Third Party Advisory"
      ],
      "source": "af854a3a-2127-422b-91ae-364da2661108"
    }
  ],
  "vulnStatus": "Modified",
  "weaknesses": [
    {
      "type": "Secondary",
      "source": "cve-coordination@incibe.es",
      "description": [
        {
          "lang": "en",
          "value": "CWE-611"
        }
      ]
    }
  ],
  "descriptions": [
    {
      "lang": "en",
      "value": "An XXE (XML External Entity) vulnerability has been detected in 52North WPS affecting versions prior to 4.0.0-beta.11. This vulnerability allows the use of external entities in its WebProcessingService servlet for an attacker to retrieve files by making HTTP requests to the internal network."
    },
    {
      "lang": "es",
      "value": "Se ha detectado una vulnerabilidad XXE (XML External Entity) en 52North WPS que afecta a versiones anteriores a la 4.0.0-beta.11. Esta vulnerabilidad permite el uso de entidades externas en su servlet WebProcessingService para que un atacante recupere archivos realizando solicitudes HTTP a la red interna."
    }
  ],
  "lastModified": "2026-06-17T06:50:27.277",
  "configurations": [
    {
      "nodes": [
        {
          "negate": false,
          "cpeMatch": [
            {
              "criteria": "cpe:2.3:a:52north:wps:*:*:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "673124C2-F045-4759-8CAF-E7FA3B993033",
              "versionEndExcluding": "4.0.0"
            },
            {
              "criteria": "cpe:2.3:a:52north:wps:4.0.0:beta1:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "5133AF2F-8DDF-4DDA-88FD-3CF2549E0860"
            },
            {
              "criteria": "cpe:2.3:a:52north:wps:4.0.0:beta10:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E94751F2-9F60-4273-A851-C864ACFA5F00"
            },
            {
              "criteria": "cpe:2.3:a:52north:wps:4.0.0:beta2:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "E99CEF0E-B714-4730-A112-E93DF41551E4"
            },
            {
              "criteria": "cpe:2.3:a:52north:wps:4.0.0:beta3:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "129F1EA8-1211-41B4-8004-2379EF3CCF7A"
            },
            {
              "criteria": "cpe:2.3:a:52north:wps:4.0.0:beta4:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "A0BE5903-85F5-4F71-B608-1B4C7DF1FF53"
            },
            {
              "criteria": "cpe:2.3:a:52north:wps:4.0.0:beta5:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "9D8027A1-D84E-4C53-BD98-164A09010B50"
            },
            {
              "criteria": "cpe:2.3:a:52north:wps:4.0.0:beta6:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "3D2A88B7-28B2-4877-9234-D3C3BFF28F8F"
            },
            {
              "criteria": "cpe:2.3:a:52north:wps:4.0.0:beta7:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "6F3521DF-72C1-4F22-BBBF-CDE84F953B92"
            },
            {
              "criteria": "cpe:2.3:a:52north:wps:4.0.0:beta8:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "DAFC6347-9AC6-48DA-94B4-8CD994BBA7F6"
            },
            {
              "criteria": "cpe:2.3:a:52north:wps:4.0.0:beta9:*:*:*:*:*:*",
              "vulnerable": true,
              "matchCriteriaId": "23AB9444-AB7C-48FA-8483-B272230F0AC1"
            }
          ],
          "operator": "OR"
        }
      ]
    }
  ],
  "sourceIdentifier": "cve-coordination@incibe.es"
}