EXPOSURES › CVE-2023-45727
CVE-2023-45727
HIGH ⌖ ON CISA KEV · EXPLOITEDNorth Grid's Proself software contains a remote, unauthenticated XXE vulnerability that allows attackers to read sensitive data or cause denial of service.
This unpatched XXE flaw in North Grid's Proself product enables remote attackers to access internal files, posing a significant risk to DIB organizations relying on this software for secure communications. The vulnerability is actively exploited in the wild, indicating a failure to patch a known issue promptly, which could lead to data exfiltration or service disruption.
Shame score — The vulnerability is actively exploited and affects multiple product lines, representing a failure to patch a known issue promptly.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack.