HIGH
Trellix IPS Manager vulnerable to XXE
Published Nov 4, 2022
7.2
HIGHCVSS 3.1
EPSS 0.58%
Description
XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the interface, which allows a saved XML configuration file to be imported.
Affected products
-
- Version unspecifiedStatusaffectedConstraints<10.1 M10
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Trellix | Trellix IPS Manager | n/a |
|
OR
- < 10.1
- 10.1
- 10.1
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
No remediation recorded yet.
Weaknesses (1)
References (1)
- https://kcm.trellix.com/corporate/index?page=content&id=SB10388 PatchVendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://kcm.trellix.com/corporate/index?page=content&id=SB10388 | PatchVendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner trellix
Published Nov 4, 2022
Updated Apr 30, 2025
Reserved Sep 27, 2022
Link CVE-2022-3340
CISA Vulnrichment
Updated Apr 30, 2025