Home
MEDIUM: 5.5 CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:NDefault status
unaffected
All versions
affected
Description
A vulnerability in GRASSMARLIN v3.2.1 allows crafted session data to trigger improper handling of XML input, which may result in unintended exposure of sensitive information. The flaw stems from insufficient hardening of the XML parsing process.
Problem types
Product status
All versions
Credits
Grady DeRosa reported this vulnerability to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-26-118-01
github.com/...p/csaf_files/OT/white/2026/icsa-26-118-01.json