NSA GRASSMARLIN
Summary
A vulnerability in NSA GRASSMARLIN, specifically related to Improper Restriction of XML External Entity Reference, allows for the disclosure of sensitive information. The affected product, GRASSMARLIN, is no longer supported by the vendor as it reached end-of-life in 2017.
IFF Assessment
FOE
The vulnerability allows for the disclosure of sensitive information, which is a negative outcome for defenders.
Severity
5.5
Medium
Defender Context
This vulnerability highlights the risks associated with using unsupported software, especially in critical infrastructure sectors like Information Technology. Defenders should prioritize identifying and migrating away from end-of-life products to mitigate the risk of exploitation, as no patches will be provided.