← Back

CVE-2014-6303

nvd nist
Published: Feb 19, 2015Modified: May 6, 2026

JSON object

Loading...
5.0
Vector
AV:N/AC:L/Au:N/C:N/I:N/A:P
Exploitability: 10.0 / Impact: 2.9
Source: NVD

Description

The Monitoring Administration pages in PNMsoft Sequence Kinetics before 7.7 do not properly detect recursion during entity expansion, which allows remote attackers to cause a denial of service (resource consumption) via a crafted XML document containing a large number of nested entity references, a similar issue to CVE-2003-1564.

Affected (1)

1 product
Sequence Kinetics
Configuration A
1 vulnerable
Vulnerable SoftwareAffected Versions
Up to 7.5

Related CWEs

Timeline

No history available yet.