Description
Lantronix Provisioning Manager is vulnerable to XML external entity attacks in configuration files supplied by network devices, leading to unauthenticated remote code execution on hosts with Provisioning Manager installed.
Problem types
CWE-611 Improper Restriction of XML External Entity Reference
Product status
Any version
Credits
Robert McLellan reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-203-02
ltrxdev.atlassian.net/...+Lantronix+Provisioning+Manager+LPM