CVE-2018-10832 EXPLOIT
5.5
MEDIUM · CVSS 3.0 · EPSS 5.8% (pctl 93)
Patch early
A public exploit exists.
Description
ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in ModbusPal, will return the contents of any local files to a remote attacker.
Scoring
| CVSS | 5.5 (MEDIUM, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
| EPSS | 5.82% — more likely to be exploited than 93% of all CVEs |
| Weakness | CWE-611 |
| On CISA KEV | no |
| Public exploit | yes |
| Published | 2018-05-11 |
| Last modified | 2026-06-17 |
Affected (1)
| Vendor | Product |
|---|---|
| modbuspal project | modbuspal |
Public exploits
| Source | Title | Date |
|---|---|---|
| exploit-db | ModbusPal 1.6b - XML External Entity Injection | 2018-05-10 |
References
→ the Explorer · watch your stack · NVD