S4E just found a high-severity finding from top 10 tcp port service scan
PlatformPlansPartners
Resources
ToolsBlogDocs
Sign Up →
high·Product Based Web Vulnerabilities·Updated Sep 26, 2025

CVE-2022-38840 Scanner

CVE-2022-38840 Scanner - XML External Entity (XXE) vulnerability in Guralp MAN-EAM-0003

Est. Time~10 seconds
Scan TypeSingle Scan
Targetsdomain, subdomain, ipv4
CostFree
2.6k
Times Used
continuous scan runs
5.9k
Continuously Checked
assets under CS
0
Vulnerabilities Found
confirmed findings
References
CVECVE-2022-38840
7.5
CVSShigh
Exploitable remotely over the internet · no authentication required.

cgi-bin/xmlstatus.cgi in Güralp MAN-EAM-0003 3.2.4 is vulnerable to an XML External Entity (XXE) issue via XML file upload, which leads to local file disclosure.

Attack Vector
Network
Privileges Req.
None
User Interaction
None
Affected
n/aby n/a
n/a
Updated Aug 22, 2026View on NVD →
Detail

Guralp MAN-EAM-0003 is a critical instrument used in seismic data acquisition to measure and analyze earth movements. Engineers, geophysicists, and researchers widely deploy it in seismological studies, oil exploration, and earthquake monitoring. The device provides real-time telemetry and data logging capabilities essential for understanding tectonic activities. Its robust design allows usage in diverse geographical locations, from remote landscapes to urban settings. The system supports various data processing modules that ensure accurate results and facilitates integration with broader monitoring systems. Regular updates and maintenance are crucial to keeping the system operational and secure.

XML External Entity (XXE) vulnerability is a security flaw that can be exploited when improperly configured XML processors process XML data. Attackers leverage the vulnerability by uploading crafted XML files containing external entity references aimed at reading local files or disrupting service functionality. If exploited, it can lead to unintended exposure of sensitive data like system credentials or configuration files. Often, such vulnerabilities arise from outdated libraries or improper parsing rules in XML processors. While XML is essential for data interchange, it poses risks when not adequately safeguarded against harmful input. Ensuring secure XML processing settings significantly reduces exposure to XXE attacks.

The XML External Entity (XXE) vulnerability in the Guralp MAN-EAM-0003 is specifically linked to the `cgi-bin/xmlstatus.cgi` endpoint. In the detected scenario, the system allows unauthorized upload and parsing of potentially malicious XML files. The root cause relates to improper input validation where external entity references within XML are neither blocked nor adequately sanitized. This could eventually permit attackers access to restricted local file paths, including the likes of `/etc/passwd`. Such a flaw leads to exposure, thereby jeopardizing system integrity. It is crucial to address it by adjusting XML parser configurations to disable external entities.

Exploiting this vulnerability can lead to serious consequences, including the unauthorized access and dissemination of sensitive information. Successful exploitation may allow attackers to read critical system files, such as password files, potentially leading to broader unauthorized system access. It can result in harmful data leaks, compromise of user credentials, and violation of privacy standards, which might escalate into compliance issues for organizations. Timely patching and implementing stringent XML processing techniques ensure these risks are mitigated. Use of regular system security audits guarantees early detection of such threats to protect system assets.

REFERENCES

Solution Advice
  • Ensure XML parsers within systems are appropriately configured to disable external entity processing features.
  • Implement input validation rules that sanitize and verify incoming XML data against harmful entities.
  • Regularly update system components to employ the latest security patches that address known vulnerabilities.
  • Periodically conduct security audits to identify and mitigate new exposure risks within XML parsing channels.
  • Train relevant personnel on potential XML security threats and the importance of maintaining secure parsing configurations.

Get AI-powered remediation steps tailored to your asset.

Try AI Solutions →

Check your infrastructure.
Right now.

11,000+ scanners. Free to start. No credit card required.

CVE-2022-38840 Scanner - XML External Entity (XXE) vulnerability in Guralp MAN-EAM-0003 | S4E