peter bassill · operator
$ cve CVE-2018-10077 JSON

CVE-2018-10077 EXPLOIT

4.9
MEDIUM · CVSS 3.1 · EPSS 8.1% (pctl 95)

Patch early

A public exploit exists.

Description

XML external entity (XXE) vulnerability in Geist WatchDog Console 3.2.2 allows remote authenticated administrators to read arbitrary files via crafted XML data.

Scoring

CVSS4.9 (MEDIUM, v3.1)
VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:N/A:N
EPSS8.08% — more likely to be exploited than 95% of all CVEs
WeaknessCWE-611
On CISA KEVno
Public exploityes
Published2018-04-20
Last modified2026-06-17

Affected (1)

VendorProduct
vertivwatchdog console

Public exploits

SourceTitleDate
exploit-dbGeist WatchDog Console 3.2.2 - Multiple Vulnerabilities2018-04-18

References

→ the Explorer  ·  watch your stack  ·  NVD