Skip to content
COOEY

EXPOSURES › CVE-2023-45727

CVE-2023-45727

HIGH ⌖ ON CISA KEV · EXPLOITED
DETAIL
SourceCISA-KEV · kev Published2024-12-03 Referencehttps://nvd.nist.gov/vuln/detail/CVE-2023-45727 ↗
⌖ EXPLOITED IN THE WILD SHAME 65/100 exploited-in-wildunpatcheddata-breach

North Grid's Proself software contains a remote, unauthenticated XXE vulnerability that allows attackers to read sensitive data or cause denial of service.

This unpatched XXE flaw in North Grid's Proself product enables remote attackers to access internal files, posing a significant risk to DIB organizations relying on this software for secure communications. The vulnerability is actively exploited in the wild, indicating a failure to patch a known issue promptly, which could lead to data exfiltration or service disruption.

Shame score — The vulnerability is actively exploited and affects multiple product lines, representing a failure to patch a known issue promptly.

▸ RECOMMENDED ACTION  Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.

DESCRIPTION

North Grid Proself Enterprise/Standard, Gateway, and Mail Sanitize contain an improper restriction of XML External Entity (XXE) reference vulnerability, which could allow a remote, unauthenticated attacker to conduct an XXE attack.

AFFECTED FEDRAMP PRODUCTS · 0
No correlated FedRAMP products.