vendor:
KYOCERA Net Admin
by:
Gjoko 'LiquidWorm' Krstic
9.8
CVSS
CRITICAL
XML External Entity (XXE) Injection
611
CWE
Product Name: KYOCERA Net Admin
Affected Version From: 3.4.0906
Affected Version To: 3.4.0906
Patch Exists: YES
Related CWE:
CPE: KYOCERA Net Admin 3.4.0906
Platforms Tested: Microsoft Windows 7 Professional SP1 (EN), Apache Tomcat/8.5.15
2018
KYOCERA Net Admin XML External Entity (XXE) Injection Vulnerability
KYOCERA Multi-Set Template Editor (part of Net Admin) suffers from an unauthenticated XML External Entity (XXE) injection vulnerability using the DTD parameter entities technique resulting in disclosure and retrieval of arbitrary data from the affected node via out-of-band (OOB) channel attack. The vulnerability is triggered when input passed to the Multi-Set Template Editor (kmmted.exe) called by the ActiveX DLL MultisetTemplateEditorActiveXComponent.dll is not sanitized while parsing a 5.x Multi-Set template XML file.
Mitigation:
Upgrade to a fixed version (3.4.0907 or later) or apply the vendor's patch.