CVE-2021-44477: GE Gas Power ToolBoxST Improper Restriction of XML External Entity Reference
GE Gas Power ToolBoxST Version v04.07.05C suffers from an XML external entity (XXE) vulnerability using the DTD parameter entities technique that could result in disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack. The vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project/template file.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is CVE-2021-44477?
CVE-2021-44477 is an XML external entity (XXE) vulnerability in GE Gas Power ToolBoxST Version v04.07.05C.
How does CVE-2021-44477 affect GE Gas Power ToolBoxST?
CVE-2021-44477 allows for disclosure and retrieval of arbitrary data on the affected node via an out-of-band (OOB) attack.
What is the severity of CVE-2021-44477?
CVE-2021-44477 has a severity rating of 7.5 (High).
How can I fix CVE-2021-44477?
To fix CVE-2021-44477, update GE Gas Power ToolBoxST to version 07.09.07c or higher.
Where can I find more information about CVE-2021-44477?
More information about CVE-2021-44477 can be found at https://www.cisa.gov/uscert/ics/advisories/icsa-22-025-01.