CVE-2022-3340: Trellix IPS Manager vulnerable to XXE
XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 allows a remote authenticated administrator to perform XXE attack in the administrator interface part of the interface, which allows a saved XML configuration file to be imported.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is CVE-2022-3340?
CVE-2022-3340 is an XML External Entity (XXE) vulnerability found in Trellix IPS Manager prior to 10.1 M8.
How does CVE-2022-3340 affect Trellix IPS Manager?
CVE-2022-3340 allows a remote authenticated administrator to perform an XXE attack in the administrator interface of Trellix IPS Manager, specifically in the part of the interface where a saved XML configuration file can be imported.
What is the severity of CVE-2022-3340?
The severity of CVE-2022-3340 is high, with a CVSS score of 7.2.
How can the XML External Entity (XXE) vulnerability in Trellix IPS Manager prior to 10.1 M8 be fixed?
To fix the XML External Entity (XXE) vulnerability in Trellix IPS Manager, it is recommended to update to version 10.1 M8 or later.
Where can I find more information about CVE-2022-3340?
You can find more information about CVE-2022-3340 in the following link: [CVE-2022-3340](https://kcm.trellix.com/corporate/index?page=content&id=SB10388)