CVE-2022-43473

A blind XML External Entity (XXE) vulnerability exists in the Add UCS Device functionality of ManageEngine OpManager 12.6.168. A specially crafted XML file can lead to SSRF. An attacker can serve 
a malicious XML payload to trigger this vulnerability.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
5.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
talosCNA
5.8 MEDIUM
NETWORK
HIGH
NONE
CVSS:3.1/AV:N/AC:H/PR:N/UI:R/S:C/C:L/I:L/A:L
CVEADP
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 84%
VendorProductVersion
zohocorpmanageengine_opmanager
𝑥
< 12.6
zohocorpmanageengine_opmanager
12.6:build126000
zohocorpmanageengine_opmanager
12.6:build126001
zohocorpmanageengine_opmanager
12.6:build126002
zohocorpmanageengine_opmanager
12.6:build126004
zohocorpmanageengine_opmanager
12.6:build126005
zohocorpmanageengine_opmanager
12.6:build126100
zohocorpmanageengine_opmanager
12.6:build126101
zohocorpmanageengine_opmanager
12.6:build126102
zohocorpmanageengine_opmanager
12.6:build126103
zohocorpmanageengine_opmanager
12.6:build126104
zohocorpmanageengine_opmanager
12.6:build126107
zohocorpmanageengine_opmanager
12.6:build126108
zohocorpmanageengine_opmanager
12.6:build126109
zohocorpmanageengine_opmanager
12.6:build126110
zohocorpmanageengine_opmanager
12.6:build126113
zohocorpmanageengine_opmanager
12.6:build126114
zohocorpmanageengine_opmanager
12.6:build126115
zohocorpmanageengine_opmanager
12.6:build126116
zohocorpmanageengine_opmanager
12.6:build126117
zohocorpmanageengine_opmanager
12.6:build126118
zohocorpmanageengine_opmanager
12.6:build126119
zohocorpmanageengine_opmanager
12.6:build126120
zohocorpmanageengine_opmanager
12.6:build126121
zohocorpmanageengine_opmanager
12.6:build126122
zohocorpmanageengine_opmanager
12.6:build126130
zohocorpmanageengine_opmanager
12.6:build126131
zohocorpmanageengine_opmanager
12.6:build126132
zohocorpmanageengine_opmanager
12.6:build126134
zohocorpmanageengine_opmanager
12.6:build126135
zohocorpmanageengine_opmanager
12.6:build126136
zohocorpmanageengine_opmanager
12.6:build126139
zohocorpmanageengine_opmanager
12.6:build126141
zohocorpmanageengine_opmanager
12.6:build126147
zohocorpmanageengine_opmanager
12.6:build126148
zohocorpmanageengine_opmanager
12.6:build126149
zohocorpmanageengine_opmanager
12.6:build126150
zohocorpmanageengine_opmanager
12.6:build126151
zohocorpmanageengine_opmanager
12.6:build126154
zohocorpmanageengine_opmanager
12.6:build126155
zohocorpmanageengine_opmanager
12.6:build126162
zohocorpmanageengine_opmanager
12.6:build126163
zohocorpmanageengine_opmanager
12.6:build126164
zohocorpmanageengine_opmanager
12.6:build126165
zohocorpmanageengine_opmanager
12.6:build126166
zohocorpmanageengine_opmanager
12.6:build126167
zohocorpmanageengine_opmanager
12.6:build126168
zohocorpmanageengine_opmanager_plus
𝑥
< 12.6
zohocorpmanageengine_opmanager_plus
12.6:build126001
zohocorpmanageengine_opmanager_plus
12.6:build126002
zohocorpmanageengine_opmanager_plus
12.6:build126100
zohocorpmanageengine_opmanager_plus
12.6:build126103
zohocorpmanageengine_opmanager_plus
12.6:build126104
zohocorpmanageengine_opmanager_plus
12.6:build126107
zohocorpmanageengine_opmanager_plus
12.6:build126113
zohocorpmanageengine_opmanager_plus
12.6:build126117
zohocorpmanageengine_opmanager_plus
12.6:build126119
zohocorpmanageengine_opmanager_plus
12.6:build126122
zohocorpmanageengine_opmanager_plus
12.6:build126139
zohocorpmanageengine_opmanager_plus
12.6:build126140
zohocorpmanageengine_opmanager_plus
12.6:build126141
zohocorpmanageengine_opmanager_plus
12.6:build126154
zohocorpmanageengine_opmanager_plus
12.6:build126155
zohocorpmanageengine_opmanager_plus
12.6:build126264
zohocorpmanageengine_opmanager_msp
𝑥
< 12.6
zohocorpmanageengine_opmanager_msp
12.6:build126001
zohocorpmanageengine_opmanager_msp
12.6:build126002
zohocorpmanageengine_opmanager_msp
12.6:build126100
zohocorpmanageengine_opmanager_msp
12.6:build126103
zohocorpmanageengine_opmanager_msp
12.6:build126104
zohocorpmanageengine_opmanager_msp
12.6:build126107
zohocorpmanageengine_opmanager_msp
12.6:build126113
zohocorpmanageengine_opmanager_msp
12.6:build126117
zohocorpmanageengine_opmanager_msp
12.6:build126119
zohocorpmanageengine_opmanager_msp
12.6:build126122
zohocorpmanageengine_opmanager_msp
12.6:build126139
zohocorpmanageengine_opmanager_msp
12.6:build126140
zohocorpmanageengine_opmanager_msp
12.6:build126141
zohocorpmanageengine_opmanager_msp
12.6:build126154
zohocorpmanageengine_opmanager_msp
12.6:build126155
zohocorpmanageengine_opmanager_msp
12.6:build126264
𝑥
= Vulnerable software versions