CVE-2018-1000828

high-risk
Published 2018-12-20

FrostWire version <= frostwire-desktop-6.7.4-build-272 contains a XML External Entity (XXE) vulnerability in Man in the middle on update that can result in Disclosure of confidential data, denial of service, SSRF, port scanning. This attack appear to be exploitable via Man in the middle the call to update the software.

Do I need to act?

-
0.24% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
9
CVSS 9.0/10 Critical
NETWORK / HIGH complexity

Affected Products (20)

Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire
Frostwire

Affected Vendors

56
/ 100
high-risk
Severity 26/34 · High
Exploitability 1/34 · Minimal
Exposure 29/34 · Critical