NSA GRASSMARLIN

Summary

A vulnerability in NSA GRASSMARLIN, specifically related to Improper Restriction of XML External Entity Reference, allows for the disclosure of sensitive information. The affected product, GRASSMARLIN, is no longer supported by the vendor as it reached end-of-life in 2017.

IFF Assessment

FOE

The vulnerability allows for the disclosure of sensitive information, which is a negative outcome for defenders.

Severity

5.5 Medium

Defender Context

This vulnerability highlights the risks associated with using unsupported software, especially in critical infrastructure sectors like Information Technology. Defenders should prioritize identifying and migrating away from end-of-life products to mitigate the risk of exploitation, as no patches will be provided.

Read Full Story →