Proself Enterprise/Standard Edition Vulnerable to XML External Entity (XXE) Attacks

CVE-2023-45727

7.5HIGH

Key Information

Vendor
North Grid Corporation
Status
Proself Enterprise/standard Edition
Proself Gateway Edition
Proself Mail Sanitize Edition
Vendor
CVE Published:
18 October 2023

Badges

πŸ‘Ύ Exploit ExistsπŸ¦… CISA ReportedπŸ“° News Worthy

Summary

The vulnerabilities affecting CyberPanel, North Grid Proself, ProjectSend, and Zyxel firewalls are actively being exploited in the wild, posing significant threats to cybersecurity. These vulnerabilities allow attackers to bypass authentication, conduct XML External Entity (XXE) attacks, modify application configurations, and exploit path traversal flaws. These vulnerabilities have been linked to ransomware campaigns and could lead to severe consequences such as data breaches, system compromises, and unauthorized access. Organizations are advised to apply vendor-provided patches or mitigation steps, discontinue use of affected products if fixes are not available, and strengthen monitoring for suspicious activity. The deadline for federal agencies to remediate these vulnerabilities is December 24 or 25, 2024, depending on the specific flaw, and private organizations are strongly encouraged to act promptly to safeguard their systems against exploitation.

CISA Reported

CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed CVE-2023-45727 as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace

The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Affected Version(s)

Proself Enterprise/Standard Edition = Ver5.62 and earlier

Proself Gateway Edition = Ver1.65 and earlier

Proself Mail Sanitize Edition = Ver1.08 and earlier

News Articles

CISA Warns of Zyxel Firewalls, CyberPanel, North Grid, & ProjectSend Flaws Exploited in Wild

The Cybersecurity and Infrastructure Security Agency (CISA) has issued warnings about several vulnerabilities being actively exploited in the wild.

3 weeks ago

CISA Warns Of CyberPanel, North Grid, ProjectSend & Zyxel Firewalls Flaws Exploited In Wild

The Cybersecurity and Infrastructure Security Agency Warns of CyberPanel, North Grid, ProjectSend & Zyxel firewalls flaws exploited in wild.

3 weeks ago

CISA Adds Critical Flaws To Known Exploited Vulnerabilities

CISA updates its Known Exploited Vulnerabilities (KEV) Catalog with three critical flaws targeting Proself, ProjectSend, and Zyxel.

3 weeks ago

References

EPSS Score

28% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • πŸ“°

    First article discovered by The Hacker News

  • πŸ‘Ύ

    Exploit known to exist

  • πŸ¦…

    CISA Reported

  • Vulnerability published

  • Vulnerability Reserved

Collectors

NVD DatabaseMitre DatabaseCISA Database4 News Article(s)
.