peter bassill · operator
$ cve CVE-2016-8348 JSON

CVE-2016-8348

9.8
CRITICAL · CVSS 3.0 · EPSS 3.5% (pctl 89)

In your normal cycle

Critical by CVSS (9.8), but no sign of active exploitation.

Description

An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.

Scoring

CVSS9.8 (CRITICAL, v3.0)
VectorCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS3.52% — more likely to be exploited than 89% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploitnone known
Published2017-02-13
Last modified2026-06-17

Affected (1)

VendorProduct
emersonliebert sitescan web

References

→ the Explorer  ·  watch your stack  ·  NVD