CVE-2021-35066: XEE
Published Jun 21, 2021
·Updated
An XXE vulnerability exists in ConnectWise Automate before 2021.0.6.132.
Affected Software
1 affected component
ConnectWise Automate<2021.0.6.132
Event History
Jun 21, 2021
CVE Published
via MITRE·07:05 PM
Data Sourced
via MITRE·07:05 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2021-35066?
CVE-2021-35066 is categorized as a medium severity vulnerability.
2
How do I fix CVE-2021-35066?
To mitigate CVE-2021-35066, upgrade ConnectWise Automate to version 2021.0.6.132 or later.
3
What type of vulnerability is CVE-2021-35066?
CVE-2021-35066 is an XML External Entity (XXE) vulnerability.
4
Which versions of ConnectWise Automate are affected by CVE-2021-35066?
All versions of ConnectWise Automate prior to 2021.0.6.132 are affected by CVE-2021-35066.
5
What can be exploited in CVE-2021-35066?
CVE-2021-35066 can be exploited to potentially gain access to sensitive data from the XML parser.