Vulnerability Details CVE-2021-20838
Office Server Document Converter V7.2MR4 and earlier and V7.1MR7 and earlier allows a remote unauthenticated attacker to conduct an XML External Entity (XXE) attack to cause a denial of service (DoS) condition by processing a specially crafted XML document.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.2%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2021-20838
-
cpe:2.3:a:antennahouse:office_server_document_converter:*
-
cpe:2.3:a:antennahouse:office_server_document_converter:5.2
-
cpe:2.3:a:antennahouse:office_server_document_converter:6.0
-
cpe:2.3:a:antennahouse:office_server_document_converter:6.1
-
cpe:2.3:a:antennahouse:office_server_document_converter:7.0
-
cpe:2.3:a:antennahouse:office_server_document_converter:7.1
-
cpe:2.3:a:antennahouse:office_server_document_converter:7.2