CVE-2025-54445
BaseFortify
Publication date: 2025-07-23
Last updated on: 2025-08-15
Assigner: Samsung TV & Appliance
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| samsung | magicinfo_9_server | to 21.1080.0 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-611 | The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability is an Improper Restriction of XML External Entity (XXE) Reference in Samsung Electronics MagicINFO 9 Server. It allows an attacker to perform Server Side Request Forgery (SSRF) by exploiting the way the server processes XML input, potentially causing the server to make unauthorized requests.
How can this vulnerability impact me? :
The vulnerability can impact you by allowing an attacker to make unauthorized requests from the server, potentially accessing sensitive information or internal systems. According to the CVSS score, it has a high confidentiality impact, meaning sensitive data could be exposed, but it has low integrity and no availability impact.