CVE-2018-18406 Details
Description
An issue was discovered in Tufin SecureTrack 18.1 with TufinOS 2.16 build 1179(Final). The Audit Report module is affected by a blind XXE vulnerability when a new Best Practices Report is saved using a special payload inside the xml input field. The XXE vulnerability is blind since the response doesn't directly display a requested file, but rather returns it inside the name data field when the report is saved. An attacker is able to view restricted operating system files. This issue affects all types of users: administrators or normal users.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://forum.tufin.com/support/kc/latest/ | CVE | Vendor Advisory |
| https://www.exploit-db.com/exploits/45808 | CVE | ExploitThird Party AdvisoryVDB Entry |
| https://www.tufin.com/ | CVE | Vendor Advisory |
| https://forum.tufin.com/support/kc/latest/ | [email protected] | Vendor Advisory |
| https://www.exploit-db.com/exploits/45808 | [email protected] | ExploitThird Party AdvisoryVDB Entry |
| https://www.tufin.com/ | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-611 | Improper Restriction of XML External Entity Reference | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| tufin securetrack | 18.1 |
CPE
Remediation
| |
| tufin tufinos | 2.16 build_1179 |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jun 24, 2019 | Initial Analysis | [email protected] |