CVE-2024-28757

Modified
Published: 10 Mar 2024, 00:00
Last modified:04 Nov 2025, 22:06

Vulnerability Summary

Overall Risk (default)
medium
40/100
CVSS Score
7.5 HIGH
v3.1 (cve.org)
EPSS Score
1.2% LOW
1% probability +0.31%
KEV
Not listed
Ransomware
No reports
Public exploits
1 found
Dark Web
Not detected

Timeline

10 Mar 2024, 00:00
Published
Vulnerability first disclosed
04 Nov 2025, 22:06
Last Modified
Vulnerability information updated

Description

libexpat through 2.6.1 allows an XML Entity Expansion attack when there is isolated use of external parsers (created via XML_ExternalEntityParserCreate).

CVSS Metrics

  • v3.1HIGHScore: 7.5CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

EPSS Trends

Current EPSS score: 1.20% Percentile: 79%

Techniques & Countermeasures

  • CWE-776Improper Restriction of Recursive Entity References in DTDs ('XML Entity Expansion')

    The product uses XML documents and allows their structure to be defined with a Document Type Definition (DTD), but it does not properly control the number of recursive definitions of entities.

Affected Systems

  • fedoraprojectfedora

    38 | 39 | 40

  • libexpat_projectlibexpat

    < 2.6.2

  • netappactive_iq_unified_manager

    na

  • netapph300s_firmware

    na

  • netapph410c_firmware

    na

  • netapph410s_firmware

    na

  • netapph500s_firmware

    na

  • netapph610c_firmware

    na

  • netapph610s_firmware

    na

  • netapph700s_firmware

    na

  • netapponcommand_workflow_automation

    na

  • netappontap

    9

  • netappontap_tools

    10

  • netappwindows_host_utilities

    na

References (10)